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Jacaban2, Evalynne (INFC) 


From: SC / VI (INFC) 

Sent: March 7, 2019 12:00 PM 

To: Leona Esau 

Subject: Smart Cities Challenge - Successful Final Proposal Submission 
Dear Leona, 


Congratulations! Your submission is ready to move onto evaluation following a completeness check (per the latest 
FAQs). 


Thank you for your cooperation, patience, and hard work, especially during the past eight months. We are truly 
honoured to have worked with you and wish you the best of luck in the competition! 


On a related matter, we have recently determined that it will not be feasible to post final proposals on the 
Infrastructure Canada website in a timely manner. Instead, we will take an approach similar to the application stage and 
publish your executive summary in both official languages on the Infrastructure Canada website with a link to the final 
proposal on your website. We understand that posting the final proposal on your website is not a reguirement 
contained in the finalist guide so we appreciate your cooperation in facilitating access to your final proposal in an open 
and transparent way. Please note that the accessibility materials you have prepared for your final proposal will still be - 
helpful in preparing various communications products to promote and share knowledge of your work. 


Once you have posted your final proposal on your website, please send us the link if you haven't done so already. If you 
anticipate that you will be unable to post your final proposal on your website within two weeks, please let us know. 


As always, we are happy to answer any guestions. The best way to reach us going forward would be at our generic 


account: infc.sc-vi.infc@canada.ca. 
Thank you. 


Smart Cities Challenge Team 
Infrastructure Canada 


infc.sc-vi.infc@canada.ca 
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COMPLETE CHECK FOR FINAL PROPOSAL 


FINALIST: Airdrie and Area 

ASSESSED BY: Susan Hwang 
VALIDATED BY: Alex Long 

APPROVAL BY: Eric Poirier 

DATE OF COMPLETION: March 5, 2019 


REQUIREMENTS COMPLETED IF NOT COMPLETED, NOTE GUIDING PRINCIPLES 
REASON 


Submitted to infc.sc- 


ACTIONS 


No extensions will e #to contact finalist 


vi.infc@canada.ca by be granted e If not resolved, # to flag to 
23:59 PST on March 5, e No exceptions will DG for decision 
2019 be made for 

lateness or 


technical problems 
(finalist must be 
able to show 
evidence of 
submission) 
Final proposal is No extensions will Assessor to save everything 
submitted l be granted in designated folders 

There is flexibility e #to contact finalist if 

on the finalist anything is missing 

video untilthe end | e lf not resolved, # to flag to 

of the week DG for decision 
Finalist video is There is flexibility e Assessor to save everything 
submitted on the finalist in designated folders 

video untilthe end | e #to contact finalist if 

of the week anything is missing 
e If not resolved, # to flag to 

DG for decision 

Preliminary Privacy - No extensions will Assessor to save everything 
Impact Assessment or be granted in designated folders 
Preliminary Rationale # to contact finalist if 
Analysis | anything is missing 
If not resolved, # to flag to 
DG for decision 


Written in one of If the final proposal # to extract the executive 
Canada’s official is submitted in a summary from the final 
languages - language other proposal and send it to 
than English or translation (if a French final 
French, a proposal, send the entire 
companion version document to translation) 
in English or French 
is reguired from 
the finalist 
Generally readable (e.g. If there are serious # to do a scan of the final 
picture is not covering formatting issues proposal and verify that all 
text, text are not that hinders text and tables, graph, etc. 
overlapping) readability, the could be read 

| finalist may need 

to resubmit 

Text-based and in either Finalist may adjust # to verify with Comms if 


MS Word (.doc or .docx) the format for INFC format is suitable for 

or a fully readable, posting purposes posting, given INFC web 
searchable, and after the deadline accessibility standards: 
selectable PDF (.pdf): If not suitable, # to contact 
format finalist 


No longer than 75 Finalist cannot # to notify finalist if final 
pages* (Financial adjust content proposal is over 75 pages 
chapter exempted) and after.the deadline i to notify finalist if INFC 
in 12 point font If the text overall is had to adjust the font and 
. smaller than 12 page count 

point font, INFC 

will adjust and 

evaluate within the 

new page count 
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Contains an executive 
summary 


Organized by these 
distinct chapters (not 
limited to these; not 
necessarily in the same 
order): 
Vision 
Performance 
measurement 
Project 
management 
Technology 
Governance 
Engagement 
Data and 
privacy 
Financial 
Implementation 
phase 
requirements 


No longer than five 
minutes 


Submitted as a file or in 
a downloadable format 


Submitted if and only if 
required 


Processed under the provisions of the Access to 


Also make a note of other 


chapters, if any 


FINALIST VIDEO 


NOTE: Accessibility document 
only contains transcripts of 
two videos in FP 


Finalist must have 
these chapters 
Finalist can have 
more chapters 
Finalist can change 
the order of the 
chapters 


Finalist may cut 
down the time for 
INFC posting 
purposes after the 
deadline 

Finalist may adjust 
the format for INFC 
posting purposes 
after the deadline 


CONFIDENTIAL ANNEX (OPTIONAL) 
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# to QC and save translated 
version into the designated 
folder 

If the chapters are not 
clearly labeled, #to doa 
light analysis of where the 
content may be and make a 
note for the Jury 


# to notify finalist if video is 
longer than five minutes 
and needs cutting down 


# to verify with Comms if 
format is suitable for 
posting, given INFC web 
accessibility standards 

If not suitable, # to contact 
finalist 


# to flag with DG if 
confidential annex is 
lengthy 


ATIA - 19(1) 


Jacaban2, Evalynne (INFC) 


From: Leona Esau 

Sent: March 4, 2019 6:34 PM 

To: SC / VI (INFC) 

Cc: ‘Dave Jackson’; Jay Stoudt 

Subject: Final Proposal - City of Airdrie & Area - 1 of 2 emails 
Attachments: Final_Proposal_Airdrie & Area_SCC.pdf 

Hello, 


Please find attached the Smart Cities Challenge final proposal submission for the City of Airdrie & Area. The Appendices 
document along with the Video submission will be sent via the City of Airdrie’s Large File Transfer site. 


| will remain the point of contact for the City of Airdrie & Area submission. 
If you have any questions or experience any difficulties accessing any of these files, please give me a call 

Alternately, you contact Jay Stoudt, Manager of Information Technology or via email 
Thank you so much for this wonderful opportunity. Looking forward to discussing our final submission with 
Infrastructure Canada and the Smart Cities Challenge Jury. 


Regards, 


Leona 


Leona Esau, Intergovernmental Liaison 
City Manager's Office, City of Airdrie 

P3403.948.8800 
C: 


Find out how you can help Airdrie become Canada's Healthiest Community 


IRDRIE 
> 7 | z 
L E RS A P À B 
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ATIA - 13(1)(d) 
Jacaban2, Evalynne (INFC) 


From: SC / VI (INFC) 

Sent: March 5, 2019 9:47 AM 

To: Leona Esau 

ce 

Subject: RE: Final Proposal - City of Airdrie & Area - 2 of 2 emails 
Hello, 


Thank you for your submission. Please consider this email as acknowledgement of receipt. We will follow up with you to 
confirm that your final proposal is ready for evaluation. 


Thank you. 


Smart Cities Challenge Team 
Infrastructure Canada 


infc.sc-vi.infc@canada.ca 


From: Leona Esau [mailto 


Sent: March 4, 2019 6:33 = 


To: SC / VI (INFC) <infc.sc-vi.infc@canada.ca> 


c MEE 


Subject: Final Proposal - City of Airdrie & Area - 2 of 2 emails 
Hello, 


Please find attached the City of Airdrie & Area's Smart Cities Challenge Appendices and Video submissions. As per 
the email | sent with our Final Proposal submission, if you have any questions or experience any difficulties 
accessing these large files, please give me a call EE, ternately, you contact Jay Stoudt, Manager of 
Information Technology A via email ESSEN 


Thank you so much for this wonderful opportunity. Looking forward to discussing our final submission with 
Infrastructure Canada and the Smart Cities Challenge Jury. 


Regards, 
Leona Esau 


Intergovernmental Liaison, City of Airdrie 
P: 403-948-8800 e 


C: 
E 


Files attached to this message 


Filename Size Checksum (SHA256) 


& Area SCC.pdf MB 
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Filename Size Checksum (SHA256) ATIA - 13(1)(d) 
Area SCC.mp4 MB 
Please click on the following link to download the attachments: 


This email or download link can not be forwarded to anyone else. 


The attachments are available until: Wednesday, 6 March. 


Message 10 MER MN 


Download Files | 
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ATIA - 13(1)(d) 


Jacaban2, Evalynne (INFC) 


From: sC / VI (INFC) 

Sent: March 5, 2019 2:49 PM 

To: Leona Esau 

Subject: RE: Final Proposal - City of Airdrie and Area - Confidential Annex 


Received — thank you. 


Smart Cities Challenge Team 
Infrastructure Canada 


infc.sc-vi.infc@canada.ca 


From: Leona Esau re M— 

Sent: March 5, 2019 1:49 

To: SC / VI (INFC) <infc.sc-vi.infc@canada.ca> 

Subject: Final Proposal - City of Airdrie and Area - Confidential Annex 


Hello, 


In my excitement to send the City of Airdrie and Area proposal yesterday, I neglected to include our Confidential Annex. 
Please find attached the document. 


If you experience any challenges downloading this file please give me a call RE 
Regards, 
Leona Esau 


Intergovernmental Liaison 
City of Airdrie 


Files attached to this message 


Filename Size Checksum (SHA256) 
Confidential 77 
Annex.pdf MB 


Please click on the following link to download the attachments: D 


This email or download link can not be forwarded to anyone else. 


The attachments are available until: Thursday, 7 March. 


Download Files 


ì ppliances https://LF1 
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Cardinal2, Patrick (INFC) 


From: 
Sent: 
To: 


Subject: 
Attachments: 


ATIA - 19(1) 


Tremblay, Jenny (INFC) 
April 9, 2019 10:17 AM 


Long, Alexander (INFC); evalynne.jacaban2 G canada.ca; Brigit Knecht 


(brigit.knecht@canada.ca) 
Airdrie : email re PPIA Smart Cities Challenge 
City of Airdrie PPIA.PDF 


rom: Leroy trover mon M 
Sent: March 21, 2019 1:53 


To: Tremblay, Jenny (INFC) <jenny.tremblay@canada.ca> 


Ge: 


Subject: Smart Cities Challenge 


Hi Ms. Tremblay, 


| have attached a letter related to our review of the City of Airdrie’s preliminary privacy impact assessment. 


Please feel free to contact me if you have any questions. 


LeRoy Brower 


Assistant Information and Privacy Commissioner 
Office of the Information and Privacy Commissioner of Alberta 


Phone: 780-422-7617 
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Office of the information and 
Privacy Commissioner of Alberta 


VIA Email 
March 21 2019 


Jenny Tremblay 
Director General 
Smart Cities Challenge Directorate 


Re: City of Airdrie County Smart Cities Preliminary PIA 
Dear Ms. Tremblay: 


I am writing to outline the results of our engagement with the City of Airdrie and the review of its Smart 
Cities project (the project) preliminary privacy impact assessment (PPIA). 


The City of Airdrie engaged with our office to discuss possible privacy issues, including a meeting to 
discuss privacy impact assessment requirements related to the project. 


We received the project PPIA on February 13, 2019. Our review of the PPIA focused on the Finalist 
Guide, Appendix 3 considerations: 


> Description of personal information or personal health information to the collected, used or 
disclosed (CUD); 

> Information flow map that outlines each CUD of personal information or health information, 
with a corresponding legal authority table for each flow; 

> Description of who you will collect personal information or health information from to 
enable the project with assessment of that person's authority to disclose the information; 

> Information governance plan; 

> Organizational privacy management framework, including related Bn HD access, 
correction, privacy and security policies; and 

» A plan that outlines the way in which you will consider privacy and security risks throughout 
the process including to complete a comprehensive PIA. 


On February 15, 2019, we wrote to City of Airdrie to outline the results of our review. We asked that 
they respond to our guestions and comments on or before March 5, 2019, and should the response 
identify a gap, to provide a plan that would outline how it will be addressed. 


On February 26, 2019, the City of Airdrie provided our office with a significantly revised and improved 
PPIA. That being said, some gaps have been identified and further privacy assessment will be required 
to ensure they are addressed. The following key gaps are important to note and ensure there is a clear 
commitment to address them should the project proceed: 


«e A more fulsome understanding of information sharing, data matching and integration is 
reguired, as well as further assessment to ensure there is legal authority for collection, use and 
disclosure of information in the project; 


Head Office. 410, 9925-109 Street NW, Edmonton, Alberta, Canada, T5K 2J8 telephone. 780-422-6860 toll-free. 1-BB8-878-4044 
fax. 780-422-5682 web. oipc.ab.ca email. generalinioGoipc.ab.ca | 
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e Robust privacy and security assessment will be essential to ensure risk has been properly 
identified and reasonable steps taken to develop and maintain administrative, technical and 
physical safeguards to reasonably mitigate risk to protect Albertans' personal or health 
information; 


* An organizational privacy management framework has been provided, but it is incomplete. The 


City of Airdrie has completed a gap assessment and commits to addressing the gaps that have 
been identified; and 


e Comprehensive notification to an Albertan who participates in the project will be required to 
ensure their authorization is informed, the purpose for collection, use or disclosure is clear and 
they understand the risks and benefits of consenting or refusing to consent. 


The PPIA provides a useful point in time opportunity to understand and address possible privacy 
implications of the project. We understand that the project will continue to be developed, and 
therefore it will be important to ensure ongoing privacy risk assessment is undertaken. 


The City of Airdrie should be required to continue its engagement with our office to address the matters 
identified above, and any other risks that may arise as the project proceeds. We will complete a 


comprehensive assessment of the steps taken to consider and reasonably mitigate privacy risk when the 
final PIA is submitted. 


Sincerely, 


eRoy 
Assistant Commissioner 


C: Leona Esau, Project Lead, City of Airdrie 
Sharon Pollyck, FOIP Head and Director, CAO's Office, City of Airdrie 
Kim Kreutzer-Work, Director, Knowledge Management, OIPC 


2|Pasge 
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APPENDIX D: PRELIMIANARY PRIVATE IMPACT ASSESSMENT DOCUMENTS AND LETTER FROM 
THE OFFICE OF THE INFORMATION AND PRIVACY COMMISSIONER | 
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” Office of the Information and 
: Privacy Commissioner of Alberta 


February 15, 2019 


Ms. Leona Esau 
Project Lead 

City of Airdrie 

400 Main Street SE 
Airdrie, AB TAB 3C3 


Re: Airdrie Smart Cities Preliminary PIA 
Dear Ms. Esau: 


| am writing in response to your preliminary privacy impact assessment (PIA) on Airdrie's Smart Cities 
project (the project), which our office received on February 13, 2018. Congratulations for being a finalist 
in this important competition. 


The PIA has been submitted approximately three weeks prior to the March 5!° final proposal deadline, 
which leaves minimal time for our office to complete a comprehensive review and provide the City of 
Airdrie with comments that may be responded to and addressed before that time. As a result, we have 
decided to focus our review of the preliminary PIA to broad and significant matters in an effort to help 
the City of Airdrie understand where there is a gap and work to be completed. Our comments focus on 
the Finalist Guide, Appendix 3 requirements, which are: 


» Description of personal information or personal health information to the collected, used or 
disclosed (CUD); 

» information flow map that outlines each CUD of personal information or health information, 
with a corresponding legal authority table for each flow; 

» Description of who you will collect personal information or health information from to 
enable the project with assessment of that person's authority to disclose the information; 

» Information governance plan; | 

> Organizational privacy management framework, including related organizational access, 
correction, privacy and security policies; and 

> Aplan that outlines the way in which you will consider privacy and security risks throughout 
the process including to complete a comprehensive PIA. 


General comments 


The preliminary PIA for this project should describe the integration between all elements of the project, 
including the My Airdrie Portal, the HealthSmart Hub and the HealthSmart App and dashboards. 
Insufficient information has been provided to describe how these interact, integrate, and the flow of 
personal or health information between them. Pieces of information have been provided, but this 
information isn't tied together to provide a comprehensive picture of the project as whole, without 

. which legal authorities and privacy risk assessment cannot be completed. 


Head Office. 410, 9925-109 Street NW, Edmonton, Alberta, Canada, TSK 2J8 telephone. 780-422-6860 toll-free. 1-888-878-4044 
fax. 780-422-5682 web. oipc.ab.ca email. generalinfo@oipc.ab.ca 
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Specific comments 
Description of personal or health information 


» The preliminary rationale assessment in relation to the HealthSmart Hub says that only 
aggregate, anonymized or de-identified information is stored within the Smart Hub. Please 
describe the steps taken to ensure the data is as described, and also outline the steps taken to 
assess risk that the data could be re-identified. In addition, please outline what steps are taken 


to protect against this data being subsequently linked or data-matched, which could then lead 
to the data being re-identified. 


information flow map and legal authority table 

> Please provide the required information flow ni and legal authority table. 
Describe who information will be collected from with corresponding legal authorities 

» This may also be included within the information flow map and legal authority table. ; E 
Information governance plan 


> We recognize that City of Airdrie governance information has been provided, but what is 
missing is a governance plan specific to this project that involves the Airdrie and Area Health 
Benefits Cooperative as a partner. 


Organization privacy management framework 


» Weare pleased to see that a compliance assessment has been undertaken. This assessment is 
based on PIDEDA and therefore it may not adequately address Alberta privacy law 
requirements. Nevertheless, it is a good starting point for assessing where there are gaps. 

> Anorganizational privacy management framework and related organizational policies is a 
Finalist Guide requirement. We see that the City of Airdrie has provided some policies but they 
are incomplete. Please provide a comprehensive privacy management framework and related 
policies. I’ve provided a link below to organizational privacy management framework guidance 
issued by our office. 


Privacy and security risk plan 


» The Finalist Guide requires a plan that outlines the way in which privacy and security risk will be = 
considered throughout the project, including completing a comprehensive PIA. Please provide a 
plan that outlines the steps that will be taken as the project proceeds to ensure proper 


consideration of privacy risks, which eventually will conclude with completion and submission of 
a final PIA. 


2|Page 
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We want to be transparent that due to the timing of the submission that is quite close to the March 5" 
deadline, we completed a quick and cursory review of the preliminary PIA. We did this in an effort to 
provide comments with enough time remaining that the City of Airdrie can consider them and respond 
on or before March 5th. The downside of this approach is that we may have overiooked or miss- 
understood something in our review, and would encourage the City of Airdrie to point this out as 
needed. 


We understand that you may not be able to address all of our questions or comments by March Sth. 
Alternatively, you may provide a detailed plan that outlines how the question or comment will be 
addressed between now and implementation of the project and submission of the final PIA. 

We request that you provide us with responses to our questions and comments on or before March 5", 
and a copy of your final preliminary PIA that is submitted to Infrastructure Canada. Should your 
response identify a gap, please provide a plan that outlines how that gap will be addressed. 


We will be providing Infrastructure Canada with comments based on the information you provide to us 
on or before March 5". 


We will complete a further comprehensive review of the final PIA should this project proceed. 
Please contact Ms. Kreutzer-Work or me if you have any guestions. 


Sincerely, 


Assistant Commissioner 


e Sharon Pollyck, FOIP Head and Manager of Legislative Services 
Kim Kreutzer-Work, Director, Knowledge Management, OIPC 


3|Page 
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Office of the Information and 


P 


rivacy Commissioner of Alberta 


February 13, 2019 


Ms. Sharon Pollyck 

FOIP Head and Manager of Legislative Services 
City of Airdrie 

400 Main Street SE 

Airdrie AB T4B 3C3 


Dear Ms. Pollyck: 


RE: Smart Cities Challenge: HealthSmart Community Operating System 
Privacy Impact Assessment 
OIPC File #: 011057 


| am writing to notify you that I have received the above referenced Privacy Impact Assessment (PIA), 
submitted under the Freedom of information and Protection of Privacy Act (FOIP). This 
acknowledgement of receipt confirms that you have submitted a PIA for review and comment. The 
submission of a PIA is not a waiver of any provision of FOIP nor is it certification that the program 
complies with the FOIP. 


Please note that our process for assigning PlAs for review has changed. PlAs will be assigned to a 
manager for review as soon as possible; however, this may take up to 4 months. 


The case file number assigned to this PIA is 011057. Please guote this number when contacting our 
office or providing any further correspondence on this file. Please retain this letter as it is proof of your 
submission. 


Sincerely, 


Jill Clayton 
Information and Privacy Commissioner 
/gc 


Head Office. 410, 9925-109 Street NW, Edmonton, Alberta, Canada, T5K 2.8 telephone. 780-422-6860 toll-free. 1-888-878-4044 
fax. 780-422-5682 web. olpc.ab.ca email, generalinfo@oipc.ab.ca 
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City of Airdrie 
Privacy Management Program Self-Assessment 


The City of Airdrie is committed to ensuring an effective Privacy Management Program is in place. 
Regardless of the success of the Smart Cities Challenge application, the City commits to implementing 
the program as outlined below. 


© & E. 
JTrGanizatic al CO. 
Buy-in from the top V | The CAO and Senior Leadership are committed 
to ensuring compliance with privacy legislation. 
Privacy Officer/FOIP Head v City Council has appointed by bylaw the City 


Clerk (Director of the CAO's Office) as the FOIP 
Head, who is responsible for overseeing the 
City's compliance with FOIP. 

Privacy/FOIP Office v The role of the FOIP Office has been defined 
and its resources have been identified and are 
adequate. Four employees, excluding the FOIP 
Head, have FOIP responsibilities built into their 
portfolios. FOIP is in addition to other p 
responsibilities. Although we do not have a um 
formal monitoring program, staff do foster a 
culture of privacy within the organization. 
Monitoring occurs informally and organically. 
The Office works to ensure that privacy 
protection is built into every major function 
involving the use of personal information, 
including product development, customer 
services or marketing initiatives. Awareness is 
at a level where departments are very good at 
bringing the FOIP Office into new or changing 
initiatives. 

Reporting X No internal reporting structure has been 

| established. 


A Breach Management Process has been 
drafted and will be taken forward to the Senior 
Leadership Team for adoption within the next 3 
months. 


Remedy: The City is committed to reaching out 

to similar sized municipalities (Grande Prairie, 

Lethbridge, Medicine Hat, Red Deer, St. Albert) : 
to see what they have in place. A reporting = 
framework will then be developed. 
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Privacy Management Program Self-Assessment 


WUTUUIT: ë 8 


Page 2 


Personal Information Inventory (PIBs) 

Policies X 
Collection, use and disclosure of X 
personal information, including 
requirements for consent and 
notification 
Access to and correction of X 
personal information 
Retention and disposal of personal V 
information 
Responsible use of information and X 


information technology, including 
administrative, physical and 
technological security controls and 
appropriate access controls 
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Partial 


The City has determined and maintains PIBs. 

The City knows: 

e what personal information it holds and 
where it is and document this assessment; 
and | 

e why it is collecting, using or disclosing 
personal information and document these 
reasons. 


Remedy: The City needs to extend its PIBs to 
include third party information and the 
sensitivity of the personal information it holds. 
Remedy: The City is committed to reaching out 
to similar sized municipalities (Grande Prairie, 
Lethbridge, Medicine Hat, Red Deer, St. Albert) 
to see what they have in place. A policy 
framework will then be developed — the City 
has earmarked the need to complete a Personal 
Information Standard as a part of the Corporate 
Information Governance Framework. 
Employees are aware of their obligation 
through training/education. 


Employees are aware of their obligation 
through training/education. The recently 
adopted Corporate Information Governance 
Framework speaks to this responsibility. City 
staff have met with every department in the 
City to share the Framework. 

The City has a Retention and Disposition Bylaw, 
Retention Schedule and Retention Schedule 
Change Process in place. Paper records are 
reviewed and appropriately disposed of on an 
annual basis. The City is currently 
implementing an EDRMS system (SharePoint) 
with a records management bolt on (Gimmal). 
All digital records within the organization 
should be managed in accordance with the 
Bylaw and Schedule by O4 2022. 

Employees are aware of their obligation 
through training/education. The recently 
adopted Corporate Information Governance 
Framework speaks to this responsibility — 
specifically the Information Security 
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Privacy Management Program Self-Assessment 


Challenging compliance 


Privacy compliance added to 
ancillary corporate policies 


Risk assessment tools 


Training and education 


Breach and incident management 
response protocols 
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Classification Standard and Handling Process. 
City staff have met with every department in 
the City to share the Framework. 

Role—based access control is accomplished 
through New/Move/Remove User Request 


Forms managed through IT. Additional systems 
(financial, budget, addressing) require 
additional permissions, again managed by IT. 
These are audited by our external auditors on 
an annual basis. 

Employees are aware of their right to complain 
about the City’s information handling practices, 
but this has not been formalized in policy. 
Remedy: An action plan will be developed to 
add privacy compliance requirements in other 
City policies. | 

The City has adopted, as a part of the Corporate 
Information Governance Framework, a Business 
System Assessment process that analyzes the 
risk and security at two stages of the system 
acquisition process — at the initial stage once 
Director approval to proceed has been obtained 
(prior to determination of requirements to 
assist with the development of requirements) 
and at the selection stage. If personal 
information is identified at Stage 1, a PIA is 
completed and then reviewed at Stage 2. 

Under the Framework, there is a formal 
approval process. This process is followed for a 
new acquisition, a major upgrade or the 
additional of a new module. 
The Service Alberta general awareness training 
for municipalities is mandatory training for all 
City employees. Legislative Services staff and 
key IT staff are required to take the 3-day 
comprehensive FOIP training program. Privacy 
is covered at orientation for new employees. 


The Corporate Information Governance 
Framework, employee acceptance letters, and 
Computer Use Policy all speak to the proper 
handling of personal information and the 
employee's responsibility therefor. 


Remedy: The City will develop a plan to ensure 
refresher FOIP training occurs. 

The City has a Breach Management Process in 
draft form that will be presented to the Senior 
Leadership Team for endorsement within the 
next 3 months. 
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Service provider management Partial 


External communication 
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The City requires contracts where third parties 
are provided with personal information. 
Although FOIP clauses are leveraged, they are 
not to the extent recommended by the OIPC. 


Remedy: Work with Procurement and other 
departments to develop and implement 
contractual responsibilities as recommended by 


the OIPC. : 

Although the City provides information on its 
website, it is not to the extent recommended 
by the OIPC. 


Remedy: Develop and implement a procedure 
for informing individuals of their privacy rights 
and the City's program controls as 

recommended by the OIPC. 
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R 
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Develop and Oversight and Review Plan X 


Assess and Revise Program Controls 
Monitor and update personal V 
information inventory 


Review and revise policies X 


Treat PIAs and security threat and risk v 
assessments as evergreen documents | 


Review and modify training and Partial 
education 
Review and adapt breach and incident X 


management response protocols 


Review and, where necessary, fine v 
tune requirements in contracts with 
service providers 


Update and clarify external V 
communication 


Page 5 


Remedy: The City is committed to reaching out 
to similar sized municipalities (Grande Prairie, 
Lethbridge, Medicine Hat, Red Deer, St. Albert) 
to see what they have in place. An oversight 
and review plan will then be developed. 


Monitoring of PIBs occurs on an ongoing basis 
to keep the inventory current and identify and 
evaluate new collections, uses and disclosures. 
Remedy: As policies are developed (as outlined 
above), evergreen clauses and a commitment 
to review will be included. 

The use of BSAs and PIAs is an evergreen 
process at the City. BSAs and PIAs, if required, 
are completed for new and changing initiatives. 
The City currently uses the Service Alberta 
general awareness FOIP training for 
municipalities. FOIP staff have identified the 
need for a higher level, organization specific 
training. 


Remedy: Revamping FOIP training has been 
identified as a 2019 business unit goal. It is 
anticipated this will be completed by year end. 
A modified FOIP training module will be added 
to new employee orientation by year end. 

As the Breach Management Process is newly 
drafted and due to be adopted by the Senior 
Leadership Team within 3 months, an 
evergreen review clause will be added to the 
document. | 

As outlined above, FOIP staff work with 
Procurement and other departments to ensure 
contract clauses are sufficient. A commitment 
has been made above to further review 
contract clauses in the short term. 


Remedy: A review process will be established 
for the future. 

As outlined above, a commitment has been 
made for FOIP staff to develop and implement 
a procedure for informing individuals of their 
privacy rights and the City's program controls as 
recommended by the OIPC. This will be done in 
the near future. 
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Privacy Management Program Self-Assessment Page 6 


Remedy: A review process will be established 
for the future. 
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Preliminary Privacy Impact Assessment 


Project Name: City of Airdrie Smart Cities Challenge 
HealthSmart Airdrie 

Custodian: City of Airdrie 

Contact Information: Sharon Pollyck 
FOIP Head 
City of Airdrie 


400 Main Street SE 
Airdrie, AB TAB OR5 


Telephone: 403-948-8800 extension 8754 
Email: sharon.pollyck@airdrie.ca 
Submission Date: February 25, 2019 
Implementation Date: TBD 
OIPC File Reference: N/A 
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Section A — System or Practice Summary 
1. What does the information system or administrative practice do? 


The HealthSmart Community Operating System (“COS”) will enable users to access and 
display information from disparate sources. By accessing information about the Social 
Determinants of Health “SDOH”), the partnership (City of Airdrie and Airdrie and Area 
Health Benefits Cooperative) believes that users will be better able to own their own health 
thereby making progress towards our Smart Cities Challenge statement of extending 
healthy life expectancy by 3+ years within 5 years. 


How the system works is outlined below. 


À System Access Point Community Operating System (COS) 
Login | 
w. MyAirdrie Portal or PE User EX Community Operating 
; COS App | Authenticated System (COS) 
| " 
Encrypted Session Started x 
= | | COS Algorithms. Mapping, — L Request V ut — Te | 
m P d Data p. : E — PEUT AR Ourcor 4 E » 
$ User Dashboard — Required to Populate j Rene o HR 
= Dashboard «— ced FOR SET 
a AN oy tanta Data Lon 
a Search Racaived 
& Query | Data 
E Processed Data Rs 21 
ui User Reguests ; Smart Service Inventory 
MyAirdrie Portal 


Users will access the COS through either the MyAirdrie portal or the HealthSmart App 
(“App”). The MyAirdrie portal and App are the front doors into the COS. 


City of Airdrie residents are currently able to access many City services (such as, paying for 
utilities and bylaw tickets, animal licensing, business licensing, viewing of assessment and 
taxation information, obtaining tax certificates, booking recreation program and facilities, 
receiving service disruption and emergency notifications) through a single sign-on process. 
The Smart Cities Challenge would allow residents to leverage this single sign-on process to 
access the COS, which would enable residents to access de-identified information. This 
service would be added to the MyAirdrie suite of services. 


HealthSmart COS 


The COS will facilitate the flow of information to and from other sources to be displayed 
temporarily on the user's dashboard. 


The COS will be comprised of four main components. 
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COS Core 


Built using open source blockchain, Nai ck Ae 
COS Core will establish an i 
infrastructure and provide 
foundational components such as 
authentication, access, and 
security. User permissions and 


SS 


Ts i COS Cor f Comm " COS Modules 
authentication will be vital to | Pros. Qe j| | Ong €> BN 
establishing a private and secure Blockchain eal System (COS) Shared Development 
infrastructure to build upon. : 

COS Community Mh. 
A v à 


COS Community will be the efforts EN 

taken to customize the core to the Data interchange 

needs of a community. 

Customization would include 

administrative tools and configurations, algorithms, logic and capacity for system 
learning and evolution over time. We will establish a standardized set of development 
protocols without the constraint of a single development language. COS Community will 
be compatible with a wide array of development languages (Python, NodeJS, Java, etc.) 
allowing for increased interoperability, innovation and shared expertise. 


COS API (Application Programming Interface) 


A Master Application Programming Interface (COS API) will be developed, enabling a 
comprehensive data interchange and providing a central mapping and access point for 
data sharing. The COS API fosters interoperability through defining protocols and 
standards for system connectivity and information sharing. Wherever possible, 
information from external data sources is expected to be de-identified prior to entering 
the COS API. This will be a contractual component of the Information Sharing 
Agreement (ISA). In the event de-identification at the source is not possible, a de- 
identification algorithm will be run to remove any potential identifiable data elements 
prior to the data entering the COS. Dashboards and user specific views and data is 
made possible through unigue data keys which reguire two levels of authentication — one 
from the user and one from the originating data source. These views allow for the data 
to be temporarily re-identified through a user initiated encrypted session. Once the 
user's session is terminated, all data will be flushed from the COS. 


COS Modules 


Taking a modular approach will improve collaborative efforts as development will not be 
confined to one vendor. COS Modules provide building blocks for shared development 
and innovation. We will be providing the capacity for new and existing applications to 
connect with the COS. COS Modules will be based on best practices/industry 
standards, allowing for future friendly development and additions based on community 
needs and technology advancements. 
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The COS will be a secure data exchange platform. Built using blockchain technologies, the 
COS provides a secure medium to receive, validate and share data for the purpose of 
providing actionable health insights to individuals, organizations, and the community as a 
whole. Data will be transactional and not stored within the COS. Data storage will be 
managed by the external data source systems in which data originates. Stored data by the 
COS is for the use of verification, security, mapping, and utilization of data, not the data 
itself. No individual or identifiable data will be stored. The COS blockchain will utilize a 
private ledger and will include data mapping, integrity monitoring, and provenance reports 
for all shared data. The COS will be subject to regular data quality assurance processes 
that address data mapping, profiling, cleansing and monitoring of data quality and integrity. 
Quarterly security audits will be implemented addressing system security, specifically 
validating no identifiable data is ever stored. 


Integrated data is necessary to support our efforts in becoming Canada’s healthiest 
community. Through a dedicated app (web — MyAirdrie Portal; mobile — to be developed) 
COS supports the ability to provide necessary information and reporting through dashboards 
to provide a measurement of healthy life expectancy. Information dashboards provide 
baselines, time trends, and performance outcomes. Data specific to the user is able to be 
displayed temporarily through an encrypted session validated by the user. Aggregated, de- 
identified data may also be surfaced to provide the user with comparative insights. Upon 
completion of the user authenticated session, all encrypted data is flushed and removed 
completely. The COS will support the capacity to authenticate and manage encrypted 
sessions through the use of standard security protocols, providing support for OpenID 
Connect, OAuth 2.0, and SAML. Users will have full transparency to session usage and 
connections through detailed audit and security logs. 


HealthSmart App 


The App will be an interface to individuals, groups, organizations, and the community to 
information. Available through any platform, the App will act as a "way finder for health," 
providing insights through a smart service inventory and user managed dashboards. The 
code required to connect and integrate data into the App will be provided to other 
municipalities. 


HealthSmart Plug-ins 


Plug-ins (works with) will connect apps and services (external data sources) based on 
specific use cases and community needs and will evolve over time. Interoperability is a core 
function of the COS. For every connection made, the partnership will be providing learning 
for other communities, including a connection "recipe book," experiential learning, and 
policies. 


2. Whatis the business rationale for the project? 


Information is housed in many different places across the municipality, province, country 
and world. When searching the Internet for information, users are not always sure of the 
credibility and reliability of the information that is displayed. Often, it is difficult to find local 
information. The City of Airdrie has a vision of becoming Canada's healthiest community. 
Our Smart Cities Challenge statement is to extend healthy life expectancy by 3* years 
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within 5 years. To do this, residents need to own their own health and become 
knowledgeable about the impact of the SDOH. This information needs to be reliable, 
credible, current and local. This COS will allow us to do this. 


The COS supports the City of Airdrie’s vision of becoming a community that provides 
evidence-informed, citizen centric, quality services. It will do this by providing a medium 
(through the App) that provides data insights informing and encouraging citizens, 
organizations, and the community as a whole towards better health. It will help to break 
down silos across the community by providing access to credible local information from 
external data sources. 


This will be measured through the calculation of a healthy life expectancy. Integrated data 
will be required to inform, guide, and motivate individuals, organizations, and the community 
as awhole. Integrated data will also provide analysts with the ability to provide necessary 
reporting and measurements in order to monitor strategies related to the outcomes of user 
engagement, increased well-being, increased health outcomes, and improved resource use. 
These four objectives have been identified as key components to achieving an increased 
healthy life expectancy. . 


Through a data quality process that addresses data mapping, profiling, cleansing and 
monitoring of data quality and integrity, the COS enables consistent reporting. It also 
provides more timely measures by simplifying key processes to access data for secondary 

“reporting. It provides an environment to match and analyze data sets from multiple 
contributing sources for measurement and analytics. 


It also provides stakeholders with a single point of contact to access data required for their 
increasing requirement to provide mandatory reporting and measures. 


3. Who are the key players? 
The key players in this partnership and the Smart Cities Challenge are the City of Airdrie 
(“City”) and the Airdrie & Area Health Benefits Cooperative (“AAHC”). Each partner 
contributes varying degrees of expertise in the areas of leadership, governance, risk and 
compliance, information technology, privacy, legal and health. 
The information needed to make the COS robust will come from the City, AAHC and 
external data sources. Information sharing agreements will be entered into with external 
data sources. 

4. Where will personal information be stored and accessed? 
No health information will be stored or accessed. 
MyAirdrie Portal 
The MyAirdrie portal has been identified as the web portal for the COS. A single-sign on 


from the MyAirdrie portal will allow users to authenticate to the COS and display COS 
dashboards and information through embedded and encrypted web technologies (e.g., 
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iFrame). The MyAirdrie portal is an existing system managed by the City independently of 
the Smart Cities Challenge. 


The MyAirdrie Portal collects credential information to allow for signup (this includes email 
address and password). MyAirdrie uses account verification to ensure email addresses are 
valid. Passwords are stored as a hashed value and cannot be reverse-engineered 
externally or internally. During sign-up, first and last name is optional and used only for 
personalizing the login page or prefilling of forms. | 


The MyAirdrie portal collects additional information depending on the service being 
requested. Phone numbers are collected as additional information for the purposes of 
providing text notifications. This collection is optional. Account numbers are attached to a 
resident's municipal address, which is linked to their credentials during sign up. No 
disclosure of personal information takes place. When registering for recreational programs 
or booking of facilities, users are redirected to the City's recreation management site. Utility 
users are redirected to the financial systems database. These functions are optional for 
users. Credit/debit card information is being disclosed to the payment processor as a flow 
through. If the user consents to having credit/debit card information stored, processing of 
payments is done through a token process and MyAirdrie stores no credit/debit card 
information. Should a user choose to provide optional banking information for pre- 
authorized payments, this banking information is stored on the external database within the 
City's firewall. A subset of pre-authorized payment information is replicated each evening to 
a separate database which is on premise. 


HealthSmart COS 


User access to the COS will be facilitated through the MyAirdrie Portal or App. No personal 
information will be stored or accessed. | 


The COS ledger and supporting databases will be stored at a secure data center located 
within Canada. We have identified potential hosting services in Alberta (Rogers, O9, 
Datahive, etc.), Montreal (AWS), and Toronto (MS Azure). Administrative access to the 
database is available only through authorized network account and password as well as 
through an authorized administrator COS user account and password. COS databases may 
also be disclosed to authorized external parties for the purposes of auditing and systems 
security checking. 


For both the web and mobile versions of the COS, additional security protocols such as 
timed logouts, location spoof checking, and forced login update protocols will be 
incorporated. | 


HealthSmart App 
The App will be accessed either through an embedded web portal or through a native 


mobile app (iOS/Android). No personal information will be stored or accessed. User 
authentication will occur through the use of standard security protocols, such as, OAuth 2.0. 
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Native, encrypted mobile apps will be developed for Apple and Android devices. Using 
device security protocols, users will have the ability to customize the amount of time for data 
to be cached, allowing for the capacity to view offline. 


Users will have the capacity to share information with other users, including friends, family, 
providers, etc. Information sharing will require an additional level of consent and individuals 
or organizations wishing to share data will need to explicitly identify which data elements are 
to be shared. Generalized sharing will not be permitted. Users who data has been shared 
with will also require additional consent to receive and view shared information. Consent 
and access forms are currently under development. 


HealthSmart Plug-ins 


ISAs will be established with each connected external data source. Contained within the 
ISA will be a list of accessible data elements and purpose of use statements. 
Updates/changes to accessible elements will require amended ISAs. Protection of personal 
information stored within an external data source will be the responsibility of the external 
data source. Only de-identified information will be permitted to flow to the COS. 


5. Why does the project need to collect, use or disclose personal information to 
achieve its objectives? 


No health information will be collected, used or disclosed. 
MyAirdrie Portal 


As MyAirdrie allows a resident/taxpayer to conduct business with the City, personal 
information must be collected to match a user with their property or services. If a 
resident/taxpayer chooses not to access City services through MyAirdrie, no personal 
information is collected. 


HealthSmart COS, HealthSmart App 


In order to meet the ongoing and future reguirements to provide necessary measurements 
and reporting for citizens, organizations, and the community, the COS will, through a secure, 
temporary, and user authenticated session integrate data from disparate information 
systems into a customized dashboard. Information displayed in the encrypted session will 
be a mix of identifiable at the individual or organization level to enable both longitudinal 
analysis and analyses across the journey towards better health. All information is encrypted 
and immediately disposed of once a session is closed. Only basic transactional data, 
indicating a session occurred and what connections were made is stored in the COS ledger. 
Contents of the ledger are encrypted and are only viewable through authentication by 
authorized parties. 


HealthSmart Plug-ins 


The external data source that chooses to share information with the COS will have already 
been collecting the personal information within their system. ISAs will ensure that the 
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external data source has complied with the requirements of their legislative authority and 
FOIP, as the receiving party. Consent will be mandatory on both sides (the external data 
source and the user) for the information exchange to occur. 


Section B — Organizational Privacy Management 


As the City is held to the highest standard for the management of personal information between 
the two partnership organizations, any work done with respect to the Smart Cities Challenge will 
be governed by and conducted under the City’s Corporate Information Governance Framework. 


Management Structure 
1. How is your senior management involved in decision-making related to privacy? 


Senior Management endorsed the City’s Corporate Information and Governance Strategy, 
Policy and Framework. An Information Governance and Management Steering Committee 
with corporate-wide representation has oversight of the City’s information framework. 


Senior Management is not directly involved in day-to-day decision-making. The FOIP Act is 
used and applied to privacy issues and any matters related to the life cycle of personal 
information. Staff seek advice and guidance from internal FOIP professionals. Where 
required, legal counsel is sought. The City’s management structure is illustrated below. The 
Director of the CAO's Office is the FOIP Head. 


A NOR te SRNR OU 
IECIGERTIUE SERUILES 
EA WE ASS AE. 


EXECHTIVE ASSISTANT: 


Paul Schulz | Juli Rodrigo: 


—— — 


DIRECTOR PEOPLE & 
ORGANIZATIONAL 


DIRECTOR CAO OFHCE 


EFFECTIVENESS 
Judy Molnar 


Sharon Pollyck 


Y HD 
DIRECTOR COMMUNITY. DIRECTOR DIRECTOR COMMUNITY. DIRECTOR 


INFRASTRUCTURE CORPORATE SERVICES GROWTH & PROTECTIVE COMMUNITY. SERVICES. 
SERVICES 
Lorne Stevens Lucy Wiwcharuk Mark Locking Michelle Lock 
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The City’s privacy structure is as follows: 


Policy Management 


2. How do you develop, approve and implement privacy policies? 


Privacy policies are developed by the Information Governance and Management Team or 
Legislative Services Team. The Legislative Services Team has oversight for any matter to 
which the FOIP Act could be applied. These policies are then reviewed and approved by 
the Information Governance and Management Steering Committee. After this approval is 
received, policies are put before the Senior Leadership Team for endorsement. Once 
approved, policies are communicated to the organization via email. They are then 
incorporated into the City’s orientation training module on information governance for new 
employees. Information governance policies are set on a maximum 5 year review cycle. 


Training and Awareness 


3. How are your employees and contractors been trained in privacy? 


Employees must take the online FOIP course for public bodies that is offered by Service 
Alberta. New employees must take the training within the first month of commencing 
employment at the City. Training is confirmed prior to receiving any access to personal 
information. If training is more than 3 years old, employees must re-take the Service Alberta 
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training model. The Corporate Information Governance Framework is a training module for 
all new employees. Typically, an employee would receive this training approximately 4-6 
weeks after commencing in their role. The City’s Avanti payroll system keeps track of 
employees’ privacy training. Legislative Services has included in their 2019 business plan 
the review of employee FOIP training. The business unit has identified a need for specific 
City FOIP training and plan to create a training program that will follow the Corporate 
information and governance training. A plan for refresher training will be put into place at 
the same time. 


Legislative Services and key IT staff attend the comprehensive provincial 3-day FOIP 
training. One Legislative Services staff member is pursuing her CIPP designation. Vendors 
are advised of the requirement to adhere to FOIP through the contract process. 


Incident Response 


4. How do you identify, investigate and manage privacy incidents. 


Staff are trained in identifying breaches and are to bring these incidents to the attention of 
the FOIP Team Lead and FOIP Head. The breach is investigated by the Team Lead, any 
systems to prevent future breaches are put in place, and the FOIP Team Lead, together with 
the FOIP Head, determine whether the City Manager, Senior Leadership Team, and the 
Office of the Privacy Commissioner need to be informed of the breach. The City’s new 
Breach Management Process has been completed will be rolled out to staff shortly to 
increase staff s awareness of what a breach is and the process for alerting the FOIP Team 
Lead of the breach. 


Access and Correction Requests 


5. How do you manage requests from individuals to access their own information and make 
corrections? 


Requests are to be made in writing to the City and identification is to be provided to confirm 
that the person requesting the correction is the owner of the information. An individual can 
appeal to the FOIP Team Lead for a final decision. Should the City refuse to correct the 


information, the requestor is provided with the information required to request a review by 
the Privacy Commissioner. 


Section C - Project Privacy Analysis 
1. Personal Information Listing 


No health information will be collected, used or disclosed. 
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My Airdrie Portal 


Information | 


Credential e Contact email address 
Information e Passwords stored as 
hashed value and 
cannot be reverse- 
engineered externally 
or internally 


Credential Optional: 

Information e First and last name 
(individual or 
organization) 


Credential Optional: 
Information e Phone number 


HealthSmart COS, HealthSmart App 


Data Elements : : 


or the collection, use | Sourceof 
| or disclosure of each Information 
(| gem | — 


Collection User 
e Sign up for access to 
services 
e Account verification 
e System authentications 
e Data matching 
e Internal 
management 
purposes 


Collection, use 
e Personalizing login page 
e Prefilling of forms 


Collection, use 
e Providing text 
notifications 


No personal information will be collected, used or disclosed. 


Data will be transactional and not stored within the COS or App. Stored data by the COS is 
for the use of verification, security, mapping, and utilization of data, not the data itself. As 
data contained within the COS is for administrative purposes, it is important to note that 
elements will not be available to non-system administrators. 


HealthSmart Plug-ins 


All personal information will be managed by the system in which it originates held and 


managed by the external data source. 
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2. Information Flow Analysis 
a. Information Flow Diagram 
| * Data is not stored on COS. Citizens must authorize which data sources can have access to which information. 
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No health information will be collected, used or disclosed. 


b. Legal Authority and Purpose Table 


Processed under the provisions of the Access to 


= Leg Authority and Purpose Table | 


managed through the 
City’s information 
assets platform, 
including census, 
business directory, and 
recreation services. 


COS retrieves data 
through a direct 
connection to the 
source system. Data is 
retrieved on-demand 
and is not stored in 
COS. 


A schema of the 
applicable elements of 
the City's data, enabling 
mapping and 
connectivity, will be 
stored in the COS. 


AAHC CHIRP is data 
that is housed with 
AAHC as an external 
data source. CHIRP 
will contain health and 
wellness data including 
wellness and population 
health, health 
outcomes, health 
utilization, and survey 
data. 


COS retrieves data 
through a direct 


identifiable and non- 
identifiable information 
depending on the use 
case and where request 
for data originates. 


Can include both 
identifiable and non- 
identifiable information 
depending on the use 
case and where the 
request for data 
originates. 
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Census 

e Toactasa 
denominator for 
measurements of 
engagement. 

e To provide aggregate 
information for 
comparative reporting 
and analytics. 

Business Directory 

e To use for information. 
source for local 
services in relation to 
health. 

Recreation Services 

e To provide information 
regarding utilization 
for information guiding 
health impact, 
planning, and 
resource allocation. 


To support mandatory 
performance reporting 
for Smart Cities 
Challenge. 


Data matching supports 
the purposes listed 
above. 


To support planning, 
improvement, 
measurement of Smart 
Cities proposal 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 
improved resource use. 


To provide users with 
information to allow for 
“Owning Own Health”. 


Information 
Protection 
Privacy Act (FOIP) 


Collection 

s. 33(c) 

Use, Disclosure 

s. 39(1)a)(c) and 
as otherwise 
authorized by FOIP 


Original data 
sources and storage 
managed by the 
City. 


Original data 
sources and storage 


external data 
source. CHIRP has 
not yet been 
developed and will 
be in development 
in parallel (but not 
inclusive) with the 
Smart Cities project 
and COS. 


Processed under the provisions of the Access to 


connection to the 
source system. Data is 
retrieved on-demand 
and is not stored in the 
COS. 


A schema of the 
applicable elements of 
the CHIRP data, 
enabling mapping and 
connectivity, will be 
stored in the COS. 


Other Data Sources will 
be any data source that 
is managed outside of 
either the City or the 
AAHC. 


Examples could include 
activity data 
repositories (e.g., 
Fitbit); open data 
repositories (e.g., 


Alberta Open data); 
government managed 
repositories (e.g., 
StatsCan, CIHI, etc.) 


Organizations may 
provide organizational 
specific data. 


For example, the local 
food bank may share 
information about food 
inventory and 
associated needs. A 
school may share 
information about 
programs and services. 
Etc. 


Depending on use case 
and end user, nature of 
data Is variable. 


An organization may 
also have an assigned 
account and will have 
the ability to manage 
authentication and 
access to connected 
sources. 


Can include both 
identifiable and non- 
identifiable information 
depending on the use 
case and where request 
for data originates. 


Can include both 
identifiable and non- 
identifiable information 
depending on the use 
case and where request 
for data originates. 
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To support planning, 
improvement, 
measurement of Smart 
Cities proposal 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 


improved resource use. 


To provide users with 
information to allow for 
“Owning Own Health”. 


To support planning, 
improvement, 
measurement of Smart 
Cities proposal 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 


improved resource use. 


To provide users with 
information to allow for 
“Owning Own Health”. 


External data 

sources are 

required to manage 

any personal 

information and will = 
be required 2 
contractually to - 

comply with their 

legal authority. 

Prior to connection 

to the COS, proof of 

an accepted PIA will 

be required. 


External data 
sources are 
required to manage 
any personal 
information and will 
be required 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PIA will 
be required. 


External data 
sources are 
required to manage 
any personal 
information and will 
be required - 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PIA will 
be required. 


7a 
7b 
8a 
8b 


Processed under the provisions of the Access to 


Citizens will be the 
leading component for 
connections and 
authorization of data 
use. Connections will 


exist, however, data will 


not be able to be 
transferred without 
authentication and 
consent by individuals. 


may be collected via 
surveys, loT, or other 
smart type devices. 


Community information 


As disparate data sources are connected, 
originating data sources will have the capacity to 


Non-identifiable data. 


Can include both 
identifiable and non- 
identifiable information 
depending on the use 
case and where request 
for data originates. 


view a City dashboard and applicable reports. 


There may be the capacity for storage and capture 
of additional elements that are made available 
through the COS. This can only be done through 
consent of data owner (individual) and custodian 


(original data source). 


COS will restrict the ability to save or import data 
without appropriate consents. Attempts to 
download or import non-consented data will be 
flagged through audits and results to user will 
appear as an encrypted uninterpretable hash. 


As disparate data sources are connected, 
originating data sources will have the capacity to 


view a CHIRP dashboard and applicable reports. 


There may be the capacity for storage and capture 
of additional elements that are made available 
through the COS. This can only be done through 
consent of data owner (individual) and custodian 
(original data source). 


COS will restrict the ability to save or import data 
without appropriate consents. Attempts to 
download or import non-consented data will be 


flagged through audits and results to user will 
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To authenticate and 
provide consent to 
existing data sources 


connected to the COS. 


Mapping and 
algorithmic data is 
stored by COS. 


To support planning, 
improvement, 


measurement of Smart 


Cities proposal 
outcomes of 


engagement, improved 


well-being, improved 
health outcomes, and 


To provide users with 


information to allow for 
“Owning Own Health”. 


Becoming Canada’s 
healthiest community 


will require involvement 


from all users. Each 


stakeholder will require 


dashboards and 


stakeholder information 
specific to the proposed 


outcomes of 


engagement, improved 


well-being, improved 
health outcomes, and 


Becoming Canada’s 
healthiest community 


will require involvement 


from all users. Each 


stakeholder will require 


dashboards and 


stakeholder information 
specific to the proposed 


outcomes of 


engagement, improved 


well-being, improved 
health outcomes, and 


improved resource use. 


improved resource use. 


improved resource use. 


External data 
sources are 
required to manage 
any personal 
information and will 
be required 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PIA will 
be required. 


Freedom of 
Information and 
Protection of 
Privacy Act (FOIP) 


Collection 
s. 33(c) 


Use 
s. 39(1)(a),(c) and 
as otherwise 
authorized by FOIP 


External data 
sources are 
required to manage 
any personal 
information and will 
be required 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PIA will 
be required. 


M ieu ud NN EN 


As disparate data sources are connected, 
originating data sources will have the capacity to 
view a dashboard and applicable reports will be 
available to the organizations managing other data 
sources. 


There may be the capacity for storage and capture 
of additional elements that are made available 
through the COS. This can only be done through 
consent of data owner (individual) and custodian 
(original data source). 


COS will restrict the ability to save or import data 
without appropriate consents. Attempts to 
download or import non-consented data will be 
flagged through audits and results to user will 
appear as an encrypted uninterpretable hash. 


As disparate data sources are connected, 
originating data sources will have the capacity to 
view a dashboard and applicable reports will be 
available to the organizations managing other data 
sources. 


There may be the capacity for storage and capture 
of additional elements that are made available 
through the COS. This can only be done through 
consent of data owner (individual) and custodian 
(original data source). 


COS will restrict the ability to save or import data 
without appropriate consents. Attempts to 
download or import non-consented data will be 
flagged through audits and results to user will 
appear as an encrypted uninterpretable hash. 


Individuals will have access to their own 
dashboards and reports with their connected data. 
Individuals will have the ability to view identified 
information about themselves inclusive to the data 
elements made available through connected 
systems. A two-part authentication process must 
be completed for this to occur. 


Individuals will have the ability to manage sharing 
and utilization of information. Individuals will also 
be able to view an audit trail of what, how, where, 
and when information is being accessed/utilized. 
Individuals will have the ability to restrict control 
and access and will be reguired to select the 
individual data element(s) to be shared. 
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Becoming Canada's 
healthiest community 
will reguire involvement 
from all users. Each 
stakeholder will reguire 
dashboards and 
stakeholder information 
specific to the proposed 
outcomes of 
engagement, improved 
well-being, mproved 
health outcomes, and 
improved resource use. 


Becoming Canada's 
healthiest community 
will reguire involvement 
from all users. Each 
stakeholder will reguire 
dashboards and 
stakeholder information 
specific to the proposed 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 
improved resource use. 


Becoming Canada's 
healthiest community 
will reguire involvement 
from all users. Each 
stakeholder will reguire 
dashboards and 
stakeholder information 
specific to the proposed 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 
improved resource use. 


External data 
sources are 
reguired to manage 
any personal 
information and will 
be reguired 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PlA will 
be reguired. 


External data 
sources are 
reguired to manage 
any personal 
information and will 
be reguired 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PlA will 
be reguired. 


External data 
sources are 
required to manage 
any personal 
information and will 
be reguired 
contractually to 
comply with their 
legal authority. 

Prior to connection 
to the COS, proof of 
an accepted PlA will 
be reguired. 


A community dashboard will be available to the Becoming Canada’s 
general public without the need for a login or healthiest community 
authentication. | will require involvement 
from all users. Each 
Data on the community dashboard will be de.- stakeholder will require 


identified and only in aggregated format. dashboards and 

stakeholder information 
specific to the proposed 
outcomes of 
engagement, improved 
well-being, improved 
health outcomes, and 
improved resource use. 


3. Notice 
No health information will be collected, used or disclosed. 


MyAirdrie Portal 


Whenever personal information is being collected, specifically at the point where residents are 
registering for a MyAirdrie account, a FOIP collection statement is provided. 


FOIP Statement 


The information collected on this page is collected under the authority of Section 33(c) of the 
Freedom of Information and Protection of Privacy Act (the “Act”) and will be used solely for the 
purposes of registering for and accessing the services under a MyAirdrie account. It will be treated in 
accordance with the privacy protection provisions of Part 2 of the Act. 


Questions concerning collection of this information can be directed to the FOIP Coordinator for the 
City of Airdrie at 400 Main Street SE, Airdrie, Alberta, T4B 3C3 or (403) 948-8816. 


With respect to the Smart Cities Challenge and the COS, the appropriate FOIP statement would 
be included on the page where a user would add the service to their dashboard. Further, when 
users choose the COS option within MyAirdrie, a pop up statement will appear that reads: — 


“You are being redirected to the HealthSmart COS operated by ....” 


Further, the City would include information on its website that would be displayed both under the 
FOIP and MyAirdrie account sections. 


HealthSmart COS, HealthSmart App 


Notice about the COS, functions, purpose and risks will be displayed prominently on system 
login screens and at any public kiosks. No data will be collected by the COS; however, the 
notices will serve to establish transparency and accountability to users. 


Should any surveys or stakeholder specific information need to be collected, this will be done 
through a separate platform and not through the COS. The survey platform, upon meeting 
connection requirements to COS, would become another connected platform. Data will not be 
collected by the COS. 
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HealthSmart Plug-ins 


Notice requirements would become a component of any ISA. 
4. Consent and Expressed Wishes 
No health information will be collected, used or disclosed. 


a. Consent 
MyAirdrie 


A users MyAirdrie site is blank until populated. by the user. Each service must be 
consciously selected to form part of the user's dashboard. During signup for new users, an 
email is sent to their address provided to allow for account verification. 


HealthSmart COS 


The COS may connect to other systems which collect health information. Please see 
HealthSmart Plug-ins below. 


HealthSmart App 


Access to the COS and authorization to utilize connected services will require digital 
consent on every sign-on. A standardized notice, providing details as to purpose, functions, 
and associated risks of COS utilization will be available for review. 


Health Smart Plug-ins 


Prior to any connections being developed to existing external data source platforms or 
systems, the said systems must provide proof of due diligence in adhering to local 
legislation and laws (including proof of an accepted PIA). This requirement will be included 
in all ISAs. Any information collected by these external data source systems, whether 
collected directly from a person or from existing source systems is the responsibility of the 
said system. It is expected that connected organizations ensure clear privacy collection 
notices exist in any facility where information is collected. A copy of these notices will be 
stored in the COS and visible to any stakeholder connecting to the platform through the 
COS. 


b. Expressed Wishes 


If data is acquired from a source system that has the ability to filter based on expressed 
wishes, this information is filtered out at the source before it is displayed through the COS. 


5. Data Matching 


Data matching will be required to support planning, quality improvement, evaluation 
throughout the continuum of becoming Canada's healthiest community. The purpose of 
linking data sets is to provide more comprehensive health status reporting. Data used for 
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data matching is acquired through connections to source systems. Data dictionaries exist for 
the majority of the data sets to minimize unintended inferences. 


Algorithms providing mapping, rules, and assumptions for data matching will be stored in the 
COS, however, no data will be stored. Data matching will only occur after secure user 
authentication and within an encrypted session. All results will be immediately removed 
after the secure user session has been terminated. 


Data matching will occur for the following purposes: 


e Data matching using information authorized for use and outlined in an ISA with the 
originating data source manager; 

e Data matching using information authorized for use by the individual or organization 
stakeholder, or 

e Data matching combining information for research purposes (a Research Agreement 
would be required prior to any data matching or disclosure). 


A data matching framework will be developed, based on methodologies and principles of 
leading health organizations (Alberta Health Services, Alberta Health, etc.). Any reports or 
dashboards will provide full transparency as the origins of information and assumptions used 
for matching data. Users will have the ability to provide or remove consent to utilize 
identified data sources. Matching will only be able to occur if authorized by the user. 


Data will be matched through the use of one/multiple user authentication protocols, including 
OpenID Connect, OAuth 2.0, and SAML. 


6. Contracts and Agreements 


a. Vendor 


Contracts with vendors to develop the HealthSmart COS, App and Master API will be 
entered into with the City after completing a municipal procurement process. While every 
contract has varying confidentiality clauses, the standard clause used by the City is: 


Freedom of Information and Protection of Privacy 

1.0 Parties and FOIP 

1.01 Both the City and Consultant, by virtue of this Agreement, are subject to the Freedom of 
Information and Protection of Privacy Act (“FOIP”) as well as any other related regulation 
reguirements governing the management of personal information. Accordingly, both 
parties have an obligation to protect the privacy of individuals to whom the information is 
related. 

2.0 Consultant’s Obligations 

2.01 Any information collected or generated by the Consultant in the course of the 
performance of this Agreement is subject to FOIP and any other related regulation 
requirements. The Consultant shail protect the confidentiality and privacy of any 
individual's personal information accessible to the Consultant or collected by the 
Consultant pursuant to this Agreement, from unauthorized access or disclosure. 

2.02 For the records and information obtained or in the possession of the Consultant in 
connection with or pursuant to this Agreement, and which are in the custody or control of 
the City, the Consultant must conduct itself to a standard consistent with FOIP when 
providing the Services or carrying out the duties or other obligations of the Consultant 
under this Agreement. 
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2.03 


2.04 


2.05 


2.06 


3.0 
3.01 


3.02 


3.03 


If the Consultant receives a request for access to information under FOIP for records in 
the custody of the Consultant as a result of this Agreement but under the control of the 
City, the Consultant must: 
a) ask the requester to make the request to the City within forty-eight (48) hours; 
b) advise the City of the request made to the Consultant and forward any copy of the 
request to the City within twenty-four (24) hours; and 
c) not disclose the information in the records unless otherwise directed by the City. 
Notwithstanding the termination or expiry of this Agreement, the Consultant 
acknowledges that information and records compiled or created under this Agreement 
which are in the custody of the Consultant remain subject to FOIP. This means that if a 
reguest is received by the City for any of these records, the Consultant shall forward the 
information and records, at the Consultant's expense, to the City within seventy-two (72) 
hours of official notification by the City. 
As applicable for City records and information under its care, the Consultant shall bear 
the burden and associated costs of records management practices reguired under FOIP. 
The Consultant shall retain all information and records received or compiled by the 
Consultant in accordance with this Agreement for a period of six (6) months from the date 
of termination of this Agreement, after which the information and records must be 
transferred to the possession of the City. 
City's Obligations 
The City will keep confidential information in all documents submitted by the Consultant. 
and accepted in this Agreement (including this Agreement itself), excluding information 
which FOIP reguires must be disclosed. FOIP includes provisions which allow the 
disclosure of business information where such disclosure would not be harmful to the - 
Consultant's business interests or where the disclosure of personal information is not 
deemed an unreasonable invasion of personal privacy as defined within FOIP. 
If the City receives a reguest for information under FOIP that includes information 
supplied by the Consultant, the City will give the Consultant notice of such reguest and 
will inform the Consultant of the information in the documents the City plans to release, 
which may affect the interests of the Consultant. The Consultant must respond to the 
City's notice in accordance with FOIP. While the City will take the Consultant's comments 
under consideration, the City is under no obligation to act upon the views of the 
Consultant. Failing receipt of a response from the Consultant, the City will proceed to 
process the request for information in accordance with FOIP. 
If the City’s response to a request under FOIP is appealed to the Office of the Information 
and Privacy Commissioner, the Consultant shall have the burden of proof as to any 
exceptions from disclosure, as defined under FOIP that the Consultant believes are 
applicable. The Consultant shall be responsible for all costs related to the appeal. The 
City will refrain from the release of the contested information until the completion of the 
appeal period. 


Contracts will be modified to ensure the requirements of the applicable privacy legislation 


are met. 


b. Partnership Agreements 


The City and the AAHC will enter into a formalized partnership agreement to ensure the 
completion and success of the Smart Cities Challenge. Each organization brings a unique 
set of skills, expertise and knowledge to the table. As the City is not currently in the health 
or health care business, the expertise and leadership of the AAHC in this grass roots 
initiative is invaluable. The agreement will outline the shared goals and expectations of the 
parties. A collaborative decision-making model will be used. Provision will be made for 
decisions that cannot be made collaboratively along with an escalating alternative dispute 
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resolution process. As the grant recipient, the City will assume fiscal responsibility for the 
Smart Cities Challenge. 


Although work has begun on a formalized partnership agreement, it will not be completed 
until such time as the Smart Cities Challenge winners have been announced. 


c. Information Sharing Agreements 


As outlined in Section A, Paragraph 4, and other places within this document, Information 
Sharing Agreements (ISAs) will be developed and used to clarify the responsibilities of the 
individual parties whenever an external data source is connected to the COS. In all cases, 
the external data source will be responsible contractually for the collection, use and 
disclosure of personal information in accordance with their privacy legal authority. Proof of 
an accepted PIA from the OIPC will be required. 


d. Research Agreements 


No health information will be stored in the COS; however, the COS will provide a medium to 
allow for access to health information stored in an external data source. 


Research involving information connected through the COS shall be done in compliance 
with Alberta’s privacy legislation. The Health Information Act and the Freedom of 
Information and Protection of Privacy Act require a research agreement to be in place 
before disclosing information for research. 


Prior to receipt of research ethics approval, consent of connected external data sources 
affected by the research will be required. Depending on the nature of the data elements 
which will be collected for the research study, additional steps in addition to source consent 
may be required. 


Before disclosing information to a researcher through the COS, the external data source will 
work with the COS Administration team to ensure that all operational and legal requirements 
are met, including a fully executed research agreement. 


7. Use of Personal Information Outside of Alberta 
MyAirdrie Portal 


A Cloud Computing Standard has been endorsed under the City’s Corporate Information 
Governance Framework. Any system housing personal information in a cloud must be hosted 
in Canada, including any backup servers. All information must be encrypted while in transit. A 
copy of the Standard is attached as a part of the Corporate Information Governance 
Framework. 


HealthSmart COS, HealthSmart App 


All information transmitted through the COS will be done through secure encryption within 
Canada. As no information is stored within the COS, the COS does not maintain any 
responsibility for how other connected systems use and transmit information. The COS only 
acts as a medium for data exchange. 
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HealthSmart Plug-ins 


As mentioned above, external data source providers will be contractually responsible to ensure 


their privacy legislation is complied with. 


Section D — Project Privacy and Security Risk Mitigation 


1. 


Access Controls 
MyAirdrie Portal 


The user would have access and be able to change their own 
of City staff is as follows: 


| Number of a 
| | User Role | 2 Stain | —. aa 
|o ___ || this Role | | o : it) : 


Database Database 2 
Administrator | maintenance 

and 

administration 
Web Configuration 
Developers for integration 

with the COS 


HealthSmart COS, HealthSmart App 


personal information. The access 


| Description on n information this | 
'" user can access. -o 
_ (include examples) 


Personal email plus any optional. 


information provided by the user (first and 
last name, phone number) 


Personal email plus any optional 
information provided by the user (first and 
last name, phone number) 


Access will be temporary and restricted to 
network or database information reguired 
to design and implement the integration. A 
formal process is reguired to attain and 
delete user access. 


No personal or health information is contained within the COS. 


Access controls will be built on standard security protocols, providing support for OpenID 
Connect, OAuth 2.0, and SAML. Regular system utilization audits will be facilitated through an 
automated system access and usage log. Predefined rules will be built-in to automatically flag 
data breaches and/or inappropriate access, and the appropriate parties (individual, organization, 
authority, etc.) will be notified. The reguired privacy legislation will be complied with. 


Individuals and organizations, as users, will be encouraged to 


information. Users will be able to manage their own accounts, 


Own their Own Health through 
including the ability to view their 


history of use and connected systems that have been authorized for the single-sign on. The 
user role grants access to connected data sources and limits access to what data sources, 


elements, and functions can be performed by the COS. 
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COS Administrators will have delegated duties to ensure that all users with access to the COS 
have access to COS security and privacy. Upon first use of COS, users will need to complete 
an online training and informational session about the COS. In addition, managed COS 
discussion boards and education libraries will be available to provide continuous learning and 


development opportunities. 


HealthSmart Plug-ins 


As mentioned above, external data source providers will be contractually responsible to ensure 
their privacy legislation is complied with. 


Privacy Risk Assessment and Mitigation Plans 


Describe the specific privacy risks you have identified for this project and how you plan to 


mitigate them. 


Unauthorized use of 
personal information by 
internal or authorized 
parties or unauthorized 
parties 


Unauthorized collection, 
use, or disclosure of 
personal information by 
external parties 


Personal information 


could be accessed by 
an authorized user 
without a need-to-know 
or by an unauthorized 
user. 

Authorized users may 
use sensitive 
information for other 
purposes than those for 
which the information 
was collected. 


External parties such 
as consultants and 
contractors may 
unlawfully collect 
sensitive information or 
use sensitive 
information for 
purposes for which it 
was not intended. They 


Ensure information is 


only accessible to those 
employees who need to 
know. Leverage IT and 
physical security 
protocols to protect 
personal information. 
Unauthorized use by 
internal parties will 
result in disciplinary 
action (up to and 
including termination). 
Ensure any access by 
authorized external 
parties is protected 
under contract. 
Unauthorized use by 
external authorized 
parties may result in 
contract termination 
and any remedies 
available under the 
contract. 


Conduct periodic 
system penetration 
tests. 

Unauthorized use by 
external authorized 
parties will result in 
contact termination and 
any remedies available 
under the contract. 


TT 
Code of Ethics (s. 


Misuse of 
Confidential 
Information and 
Breach of the 
Code of Ethics) 
Performance 
Outcomes 
Guideline (s. 
Corrective Action) 
IGM Policy 
Information 
Security 
Classification (s. 
Confidential) and 
Handling Process 
(s. Confidential) 
Computer Use 
Policy (currently 
under review) (s. 
1.1.2, 1.3, 50). 
(b), (n), (t), 6, 8) 
Privacy Breach 
Management 
Process 


Formalized 
contract 
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may also intentionally 
or intentionally disclose 
sensitive information to 


Loss of integrity of 
personal information 


Loss, destruction, or loss 
of use of personal 
information 


Contractor or business 
partner collects, uses, or 
discloses personal 
information in 
contravention of FOIP or 
City policies 


unauthorized 
individuals. 


Personal information is 
no longer accurate and 
cannot be relied upon. 


Customer provides 


updated information to 
one department that 


does not get shared 


with other departments. 


Information may be 
accidentally lost or 
corrupted due to 
human error or by 


malicious codes such 
as viruses. Malicious 
codes or human factors 
may cause information 


to be unavailable to 


authorized users when 


and where needed. 


Third party acts without 


permission from the 
City. 
Third party acts in a 


way not sanctioned by 


the City. 


HealthSmart COS, App, Plug-ins 


City staff take every 
opportunity to verify 
personal information 
while conducting day- 
to-day operations. 
Explore the potential of 
having taxpayers 
update personal 
information annually 
with tax notices. 


Only authorized users 
have access to 
personal information. 
Education/training on 
the importance of 
managing personal 
information 
appropriately. 
Adherence to 
Information Security 
Classification Standard 
and Handling Process. 


Ensure that any parties 
that information is 
shared with are 
authorized. 


IGM Policy 
Information 
Security 
Classification (s. 
Confidential) and 
Handling Process 
(s. Confidential) 
Computer Use 
Policy (s. 1.1.2, 
1.3, 5(a), (b), (n), 
(t), 6, 8) 


IGM Policy 
Computer Use 
Policy (s. 1.1.2, 
1.3, 5(a), (b), (n), 
(t), 6, 8) 


Formalized 
contract 


It is important to note that the COS has not yet been developed and, as a result, has not yet 
been through a security review. In preparation for development, we have outlined potential 
privacy and security risks in the table below. No health or persona, information will be stored or 


accessed by the COS. 


e oo a oe 


personal information 


by internal or 
authorized parties or 
unauthorized parties 


“Personal 


. Description o | p 


information could 
be accessed by an 
authorized user 
without a need-to- 
know or by an 


. Mitigation Strategy - 


All COS Users are assigned a a 
unique Userid. 
All COS users are subject to COS 
standards. These may include: 
o Code of Conduct 

o Information Access and 


Policy Reference 


Policies are - 
planned for 
development, 
which may include: 
o Code of 
Conduct 
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unauthorized user. 
e Authorized users 
may use sensitive 
information for 
other purposes 
than those for 
which the 
information was 
collected. 


Acceptable Use Policies 
o Confidentiality Statement 
o COS User Agreement. 

e All COS users complete annual 
continuing education modules that 
include information privacy and it 
security awareness. 

e Access to authorized users within 
the COS is based on the need-to- 
know principle (authorized users 
will have limited access to data 
according to their role). 

e Logging and auditing are 
implemented within the production 
environment of the COS and 
users are advised their activity is 
audited through the User 
Agreement. 

e Breaches are reported and 
investigated according to City 
Policies. 

e An Information Security 
Classification Standard and 
handling process have been 
developed by the City. This will 
be applied to each data element 
in all data assets connected 
through the COS. This will enable 
more efficient auditing as well as 
assist in classifying information 

products appropriately. 


Unauthorized 
collection, use, or 
disclosure of 
personal information 
by external parties 


External parties 
such as 
consultants and 
contractors may 
unlawfully collect 


External parties/consultants are 
subject to COS standards and 
agreements These may include: 
o COS User Agreement 

o COS Data Manager 


personal Agreement 
information or use o IT Access Request Form. 
personal e Access to authorized users within 


the COS is based on the need-to- 
know principle (authorized users 
will have limited access to data 
according to their role). 

e_ A guarterly review of individuals 
who have accessed the COS will 
be validated against the list of 
authorized COS users by the 
COS Administration. | 

e ISAs have been established to 
limit use and disclosure of COS 
data connections by external 
users. 

e Users are provided with 

information that an approved 
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information for 
purposes for which 
it was not intended. 
They may also 
intentionally or 
unintentionally 
disclose sensitive 
information to 
unauthorized 
individuals 
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COS User 

COS Audit 

Framework 

User Account 

Standard 

COS Information 

Access and 

Acceptable Use 

Policies 

COS 

Confidentiality 

Statement 

e Privacy Breach 
Management 
Process 

e Information 
Security 
Classification 
Standard and 

Handling Process 


Policies are 
planned for 
development, 
which may include: 
COS User 
Agreement 
COS Data 
Manager 
Agreement 

IT Access 
Request Form 


Loss of integrity of 
personal information 


Loss, destruction, or 
loss of use of 
personal information 


Contractor or 
business partner 
collects, uses, or 
discloses personal 
information in 


contravention of legal 


authority 


Monitoring 


MyAirdrie Portal 


Personal 
information is no 
longer accurate 
and cannot be 
relied upon 


Information may be 
accidentally lost or 
corrupted due to 
human error or by 
malicious codes 
such as viruses. 
Malicious codes or 
human factors may 
cause information 
to be unavailable 
to authorized users 
when and where 
needed. 


Third party acts 
without permission. 


external data source is under an 
agreement as well as specifics on 
any limitations for use and/or 
disclosure within the agreement. 


Accuracy of data will be 
addressed in detailed ISAs, which 
may result in termination of 
external data source connections. 


Use of data and services will all 
require detailed ISAs. 

Only authorized system 
administrators control access 
rights to the COS. 

As the COS application is 
managed by the joint governance 
structure of the City and the 
AAHC, the COS follows the 
standard City backup/archival 
policies and City Antivirus 
implementation. In the event of 
accidental loss of data, the 
administrative data 
(mapping/algorithms/configuration 
s, etc.) can be re- 
created/recovered. 

The core COS environment is 
read only for anyone except 
system administrators. 


Authentication protocols require 
both authorized user and 
authorization from external data 
source. 

Requirements for PIAs and 
compliance with privacy 
legislation is enforced. 


Formalized 
contract 


Policies are 
planned for 
development, 
which may include: 
o Access to 
Information 
(physical 
electronic, 
remote) 
Information 
Security and 
Privacy 
Safeguards 
Monitoring and 
Auditing of IT 
Resources 
COS 
Operational 
Level 
Agreement 


User level actions are logged with respect to successful and unsuccessful attempts. No 
notifications are sent to administrators. Notifications are sent whenever invalid attempts to 
access or change data occur. Logs are only reviewed upon request. 


HealthSmart COS, App, Plug-ins 


Security controls will be reviewed as a part of the COS annual review of the PIA. 
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a. Repository Logging Capability 


User and system activities are defined as: 


User and system activities: All successful accesses and operations performed by an 
authorized user (e.g., logging onto the COS accessing and querying data) are recorded 
(logged) and can be monitored. It includes both appropriate and inappropriate activity. 
User and system activity exceptions: All attempted accesses and operations performed 
by an authorized user that occur outside the expected activity (e.g., unsuccessful logon, 
unsuccessful access). 


o Logging and auditing of the COS user activity is logged and monitored in accordance 
with a, to be developed, COS Audit Framework. 
o Activities logged include: 


Successful and unsuccessful logons; 

Inactive Users; 

Registration Patterns; 

Network account and DB account mismatch; and 
COS Usage (Top 10 and usage by business). 


b. Audit Process 


The COS will have regular audits established to monitor user activity. Audits will be 
conducted on a scheduled basis and may include. | 


Proactive — sampling the audit logs to look for possible inappropriate use or activity: 


User Sessions — Monthly; 

Granting Privileges — Monthly; 

Use of data sources containing potentially personally identifiable data (Fine Grained 
Auditing) — Monthly; and 

User Access — Quarterly (random); Bi-annual (full). 


Reactive — reviewing specific audit logs when unusual activity is suspected: 


The COS Data Sharing Access and Audit will be responsible for completing and 
reporting any findings of these audits to the established information governance 
structure. 

The User Session Audit will be a monthly audit that potentially identifies unauthorized 
access through the potential sharing of passwords where network user name is different 
from logon, user is logged on to more than one location at the same time, and where 
users are logged on outside the expected usage hours. All records will be grouped 
network user name by COS user name and date. 

The Grant Audit will be a monthly exception checking audit to identify potential 
unauthorized access through granting privileges where tables or views have been 
granted access or where access to tables/views have been granted. 

The Use of Data Sources Containing Potentially Personally Identifiable Data Audit will 
be a monthly audit of randomly selected users. User queries will be audited to identify 
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inappropriate use including the use of selective criteria (i.e., specific: unique identifiers, 
locations, dates, etc.) that would not be typical uses. 
e The User Access Audit will be a quarterly audit that is a validation of authorized access. 


In addition to proactive audits, where unusual activity is suspected, the Fine Grained 
Auditing logs capture all queries where identifiable data has been selected. The logs of 
specific users would be reviewed in detail where there is any question of unusual activity 
through any of the proactive audits. 


The COS is envisioned to have administrative centric dashboards to enable easy viewing of 
user activity for monitoring. Patterns of inappropriate activity can be easily spotted during 
the monthly review, enabling timely remediation and investigation. 


4. PIA Compliance 


The PIA will be reviewed frequently during the five-year implementation phase. Every time a 
new component or external data source is brought on, the PIA will be reviewed to ensure it is 
accurate and relevant. Post implementation, the PIA will be reviewed for accuracy and 
relevancy as new external data sources are engaged. At a minimum, the PIA will be diarized to 
be reviewed on an annual basis. 


Should significant differences exist between the COS connections, functions, and requirements 
and what is described in the existing PIA, consultation will occur on whether an amended PIA 
will need to be prepared for submission to the OIPC. Significant differences consist of one or 
more of the following: 


e multiple (greater than three) amendments to the PIA exist; 

e changes to the collection, use or disclosure of health or personal information; 
e changes to user access to health or personal information; or 

e changes to the flow of health or personal information. 


Amendments are required whenever changes are made to the COS that are not described in 
the PIA. Changes to the COS that may require an amendment consist of one or more of the 
following: 


e changes to the collection, use or disclosure of health or personal information; 


e changes to user access to the health or personal information; or 
e changes to the flow of health or personal information. 


E. Policy and Procedures Attachments 


"Policy Description Attachment Tite(s) | p F2 


7 
| Reference | 


No formal policy has been 
created. Bylaw No. B- 
31/1999 establishes the 
City Clerk as FOIP Head. 


This is a broad policy that enables 
privacy roles and accountability within 
your organization. Sometimes called a 
privacy charter, this policy does not 
provide detailed work instructions, but 
rather sets out responsibilities and 


Privacy. 
Accountability 


37 


The City follows the FOIP 
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commitments in relation to privacy. 


This policy should include: 

* Where privacy fits into your 
organizational structure 

* Who is responsible for privacy, 
including who is responsible for 
responding to privacy complaints 

* Who is responsible for information 
security 

* Commitment to protect 
confidentiality and to collect, use and 
disclose personal information in a 
limited manner 

e Commitment to maintain accuracy of 
personal information 

e Commitment to provide privacy 
training and awareness to employees 

+ Commitment to maintain technical 
and administrative safeguards to 
protect personal information 

* Right of access to personal 
information and right to request 
corrections 

* Schedule for periodic 
privacy policies 

Your process and timeframes for 
responding to formal requests from 
individuals for access to 

their own personal information. 
Include references to appropriate fee 
schedules or other policies for charging 
fees to process access requests. If you 
require that individuals fill out a form 
to make access requests, include it 
here. You should also consider a 
process for responding to informal 
requests or making routine disclosures. 


Access to Personal 
Information 


Your process and timeframes for 
responding to individuals who ask you 
to correct their personal 

information. Include your process for 
responding to these requests and 
describe how you inform individuals of 
your decisions to grant or refuse 
corrections. 


Correction Requests 


review of 


Act 


Structure outlined in 
Section B(1) above. 


FOIP Act 
FOIP Access Form 
Bylaw No. B-31/1999 


No fee is charged for 
access to a person's 
personal information as 
outlined in the Act. 


Wherever possible, 
access requests are 
managed in a timely 
manner outside the formal 
FOIP process. 

FOIP Act 


Requests are to be made 
in writing. 
Acknowledgement is 
provided to the requester 
upon completion. 
Although no specific 
timelines are identified, 
City staff respond to 
requests for correction in 
the moment unless there 
are extenuating 
circumstances. 
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TRAINING, 
AWARENESS 
& SANCTIONS 


Collection of Personal 
Information and 
Notice 


Use of personal 
Information 


Disclosure of 
Personal Information 


Processed under the provisions of the Access to 


Your privacy training program for 
employees and others that will have 
access to personal information in your 
custody. This policy should include 
sanctions for not complying with your 
privacy policies. 


Acceptable reasons for collecting 
personal information, which should 
include statutory authority under the 
FOIP or other relevant legislation. 


Include examples or descriptions of 
how you notify individuals about why 
you are collecting their information. 
Acceptable uses of personal 
information in your organization 


Reasons why your organization 
discloses personal information to other 
organizations or persons. 


This policy should cover: 


Disclosure without consent 
Disclosure with consent 
Disclosure of non-identifying 
information 


Service Alberta Online 
Public Body Training is 
mandatory for all 
employees. 


All staff members in 
Legislative Services and 
key staff members in 
Information Technology 
take the 3-day privacy 
management course 
through Service Alberta. 


Breaches or non- 
compliance are managed 
under the City’s 
performance 
management program 
which spans the spectrum 
from a verbal discussion 
to dismissal. 


The City’s Computer Use 
Policy (currently under 
review) outlines how 
systems are to be used 
and accessed and 
prohibits unauthorized 
access to personal 
information. 


Section 33(c) of FOIP Act 
and other bylaws as 
appropriate. 


FOIP statement included 
on forms that collect 
personal information. 


FOIP Act. All use is 
based on need to know 
and determined in 
conjunction with 
Legislative Services. 


FOIP Act 
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Release in statistical 
format only — each 
request reviewed ona 
case-by-case basis. To 
date, the City has not 
received a research 
request. 


How your organization handles 
research, requests from researchers 
including approval process for research 
requests and agreements with 
researchers 


Third Parties How you ensure that third parties, 
which include contractors and 
information managers, protect your 
organization’s personal information. 
This policy should include privacy 
requirements for third-parties, review 
of third-party compliance, 
requirements for out-of-province 
information managers. 


PIAS Circumstances that trigger your 


organization to conduct a privacy 
impact assessment. This policy should 
Records Retention 
and Disposition 


Research 


Third parties enter into a 
contract, especially if 
personal information is 
involved. 


Sample wording is 
included in Section 6(a) 
above. 


No compliance review 
unless triggered by an 
incident/complaint which 
would be investigated. 


Software implementation 
and offsite storage of 
information. The City has 
a Business Systems 
Assessment (“BSA') 
process that requires 
identification and 
management of personal 
information at various 
stages in the software 
acquisition process. 


describe who is responsible for 
conducting PIAs and how often they 
are reviewed. 


A PIA is triggered by any 
business process that 
contains personal 
information. The PIA is 
completed by Legislatives 
Services, IT, Information 
Governance and the 
requesting business unit. 


PIA’s are reviewed when 
changes to business 
systems occur. 


How long you keep records containing | Retention of records 
personal information and what you do | containing personal 

with them once they are no longer information varies and is 
needed. Include references to any governed by the 
statutory or professional records Information Governance 
retention and disposition schedules and Management Policy, 
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Information 
Classification 


Risk Assessment 


Physical Security of 
Data and Equipment 


Processed under the provisions of the Access to 


you follow. This policy should also 
include a process to securely dispose of 
personal information when no longer 
needed. 


Information should be protected at a 
level commensurate with its sensitivity 
and the risks it faces. Describe how you 
classify personal information in order to 
determine the most appropriate level of 
security. 


New risks to the confidentiality, integrity 
and availability of personal information 
may arise over time as technology and 
business processes evolve. This is your 
policy for conducting periodic risk 
assessments to assess the effectiveness 
of your privacy policies. 


Records Retention and 
Disposition Bylaw No. B- 
11/2017, Retention 
Schedule and Retention 
Schedule Change 
Process. 


The City is currently 
implementing an EDRMS 
with a records retention 
bolt on, which will provide 
the City with the ability to 
manage its electronic 
records. The City has 
adopted an Information 
Governance and 
Management Strategy 
whereby the City will be 
digital by 2022. 


Information is classified 
according to the 
Information Security 
Classification Standard 
and Handling Process. 


BSAs are required as 
business systems evolve 
over time. The BSA is a 
risk assessment tool. 
BSAs are approved at the 
IGM Steering Committee 
(“IGMSC”). It is expected 
the Corporate Information 
Governance Framework 
will be complied with. In 
the event a BSA does not 
comply with the Corporate 
Information 

Governance Framework 
and risks cannot be 
mitigated to the 
satisfaction of the IGMSC, 
a business unit may 
appeal the decision of the 
IGMSC to the Senior 
Leadership Team. 


Formal review processes 
for evolving business 
processes are being 
investigated. 
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Networking and 
Communications 
security 


Processed under the provisions of the Access to 


information in paper and electronic form. 


This policy should describe how you 
secure your workspaces, computers, fax 
machines, copiers, and other office 
equipment. Pay special attention to 
securing mobile equipment, such as 
notebook computers and mobile data 
storage devices. 


Measures you take to secure your 
network and communications 
infrastructure. This could include such 
controls as malware (anti-virus) 
protection, firewalls, intrusion detection 
systems and encryption. 


information is to be locked 
up. Filing cabinets and 
storage receptacles are 
provided upon request. 


The Information Security 
Classification Standard 
addresses appropriate 
security based on 
classification. 


The Computer Use Policy 
deals with technology 
related devices. 


Network Based 
Inbound and outbound 
Fortinet firewall that has 
identity awareness. This 
allows IT to verify that 
the user(s) have policies 
applied based on 
business requirements 
for access internal and 
externally. 
Application awareness 
and control of inbound 
and outbound 
granularity. When 
polices are set, control 
of what application is 
allowed to traverse 
internal/external based 
on business 
requirements. 
Design of the network 
infrastructure to 
segment networks to 
control data flow 
between networks. This 
allows IT to control data 
flow of systems to only 
allow access to systems 
that they truly require. 
The inherited design 
allows for better control 
and logging of the 
communications. 
Intrusion prevention 
system to detect and 
prevent inbound and 
outbound 
communications that are 
known to contain 
dangerous 
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communications. 


e Active Directory users. 
Single sign on for most 
new applications that 
have been 
implemented. 


Desktop Based 

e Desktop anti-virus and | 
host based intrusion B 
detection. 

e Application control 
based on specified 
policies specified at the 
desktop level. 
Applications such as 
download managers, 
encryption software, 
email clients, file sharing 
applications and so on 
can be controlled from 
leaving the desktop 
level. 

Control and detection of 
Malware and malicious 
and suspicious behavior 
that may originate from 
desktop. 

Data Control of 
documents and or data 
that are marked as 
being or other definable 
content or file 
information. Data can be 
controlled to prevent 
leakage of data or to 
monitor and report of 
the identified leakage. 


General 

e VDI (Virtual Desktop) 
allows interaction with 
the desktop and data. 
Data doesn’t leave the 
network environment 
preventing data loss. 

e All new mobile device 
technologies allow for 
full device encryption. 
Entry into the network 
requires that a two 
factor authentication be 
passed. (Something you 
know = username and 
password. Something 
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you have = cell phone 
device.) 
Email communication 
between handheld and 
mail server are 
encrypted during 
communications. 
Using secure https 
encryption between 
clients and server 
applications. 
All data centres/wiring 
closets physically 
secured with key pass 
and code. Some 
locations have video 
surveillance. 
New employees are 
assigned access levels 
that are determined by 
their position and 
confirmed by their 
Team Leader through a 
New User Request 
Form submitted to IT. 
Any time an employee 
changes roles or leaves 
the organization, a Move 
User or Remove User 
Request form is 
completed and submitted 
to IT. IT reviews the 
information prior to 
providing or removing 
access. This process is 
reviewed by the City's 
external auditors on an 
annual basis. 


Identifying and verifying users of your 
personal information, deciding what 
information they need to use, and 
making changes when users change 
positions or leave. Identification and 
verification includes assigning 
usernames, passwords and tokens. 


Access Controls 


120 


121 
122 


Database Access Forms 
are used for any time an 
employee needs access 
to a database containing 
personal information. The 
form is completed by the 
requestor, signed off by 
the Team Leader and 
forwarded to Legislative 
Services, who confirm 
that the reguestor's FOIP 
training is up to date (no 
more than 3 years old). 
The FOIP Head or Team 
Lead signs off on the form 
to grant permission for 


123 
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access. 


The IT Service Desk 
tracks all tickets, including 
the forms above. All are 

auditable. 


How you ensure that users of the 
personal information comply with 
policies. This policy should describe what 
you monitor to ensure compliance, 
frequency of review and triggers for a 
formal audit/review or activation of your 
incident response plan. 


Monitoring and Audit No formal monitoring or 
audit processes are in 
place. Compliance is 
done on an informal basis 
and triggered by 


complaint or observation. 


Your plan to deal with contraventions of 
legislation and your own privacy policies. 
Plan should: 


The City does not have a 
formal plan in place. 


Incident Response 


Informally, FOIP staff 
conduct an internal 
investigation and 
depending on the nature 
of the breach, corrective 
action would be 
undertaken with the 
responsible staff member. 
Depending on the nature 
of the breach, senior 
management and the 
OIPC may be advised. 


Define what constitutes a privacy 
incident {or levels of privacy incidents) 
Identify members of an incident response 
team 

Describe the process to bring incidents to 
attention of senior management and 
engage them in the process 

Process to determine whether to notify 
individuals affected by the incident 
Process to determine whether to notify 
to OIPC 


The City follows its 
Breach Management 
Process. 


How you ensure personal information is 
available when needed. This includes 
your plans to back-up data and your 
plans for disaster recovery, based on 
business need 


Snapshots of systems are 
regularly captured and 
replicated to another data 
centre in a separate site. 
Backup tapes are also 
stored in a locked vault off 
site. 


Business Continuity 


Ensuring that changes to systems do not 
adversely affect the confidentiality, 
integrity or availability of personal 
information. 


A change to a system 
would trigger a new PIA. 


Change Control 


There is a formal Change 
Management Advisory 
Board within IT where all 
changes to systems are 
thoroughly reviewed prior 
to implementatio 


Project Specific Include any project-specific policies . | N/A | 
Policies 
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BYLAW NO. 31/99 
OF THE CITY OF AIRDRIE 
IN THE PROVINCE OF ALBERTA 


Being a Freedom of Information and Protection of Privacy bylaw. 


WHEREAS, pursuant to Section 89 of the Freedom of Information and Protection of Privacy 
Act, S.A. 1994, c. F-18.5, the City of Airdrie must designate a person or group of persons as the 
head of the municipality for the purposes of the Act: 


AND WHEREAS, pursuant to Sections 87 and 89 of the Freedom of Information and 
Protection of Privacy Act, the City of Airdrie may set any fees payable to the municipality for services 
under the Act and Regulations; 


NOW THEREFORE the Municipal Council of the City of Airdrie in Council duly assembled 
enacts as follows that: 


PART I — PURPOSE, DEFINITIONS AND INTERPRETATION 
1. The purpose of this Bylaw is to establish the administrative structure of the City of Airdrie in 
relation to the Freedom of Information and Protection of Privacy Act and to set fees thereunder. 
25 In this Bylaw, unless the context otherwise requires: 
"Act" means the Freedom of Information and Protection of Privacy Act, S.A. 1994, C. F-18.5; 


"Applicant" means a person who makes a request for access to a record under Section 7(1) of 
the Act; 


"Municipality" means the City of Airdrie and includes any board, committee, commission, 
panel, agency or corporation that is created or owned by the City of Airdrie and all the 
members or officers that are appointed or chosen by the City of Airdrie but does not include 
the Airdrie Municipal Library Board and Airdrie Community Lottery Board. 


"City Clerk" means the person employed as the City Clerk of the City of Airdrie and includes 
any person who holds the position of City Clerk in an Acting capacity; 


“Province” means the Province of Alberta. 


3. The headings in this Bylaw are for reference purposes only. 


PART II - DESIGNATED HEAD 


4. For the purpose of the Act, the City Clerk is designated as the Head of the municipality. 
PART Ill — FEES 
5. Where an Applicant is required to pay a fee for services, the fee payable is in accordance with 


the Freedom of Information and Protection of Privacy Regulation, AR 200/95, as amended from time 
to time or any successor Regulation that sets fees for requests for information from the Province. 


Processed under the provisions of the Access to Page 59 of 341 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


ATIA - 19(1) 


Bylaw No. 31/99 
Page 2 


PART IV — GENERAL 


6. This Bylaw comes into effect on October 1, 1999. 


READ a first time this 20" day of September, 1999. 
READ a second time this 20^ day of September, 1999. 


READ a third time this 20^ day of September, 1999. 


EXECUTED this ay day of September, 1999. 


CITY CLERK 
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ioi [D | eetcctonor privacy Act Request to Access Information 
rotection of Privacy Act 


Personal information on this form is collected under Alberta’s Freedom of Information and Protection of Privacy 
Act and will be used to respond to your request. See instructions for completing this form. 


Title (optional) Last Name 


About you First Name 
Name of Company or Organization (if applicable) | 
Mailing Address Street City/Town/Village Province Postal Code 
Telephone Number (daytime) Telephone Number (evening) 
E-mail Address 
About your 1. What kind of information do you want to access? 
request L| General information (An initial fee of $25 is required — see instructions for explanation of fees.) 


L] Your own personal information (No initial fee is required for personal information.) 
2. To which public body are you making your request? (Please fill in the name of the public body 


that has the records you wish to access. For a complete listing of public bodies, consult the Directory of 
Public Bodies on the FOIP website at foip.alberta.ca.) 


WI ————'Oe eU OU H-—— 


3. Do you want to: B receive a copy of the record? OR || examine the record? 


Aboutthe 1- What records do you want to access? Please give as much detail as possible. (/f you want access to 


information your own personal information, be sure to give all your previous names. For another person's information, 
you want to you must attach proof that you can legally act for that person.) 
access 


2. What is the time period of the records? Please give specific dates. (See instructions for details.) 


Your signature Signature Date 


Where to send Send your completed request form, and initial fee if applicable, to the FOIP Coordinator of the public body that has the 
your reguest records you wish to access. For contact information, consult the Directory of Public Bodies on the FOIP website at 
foip.alberta.ca. 


Reguest Number NE — iun 


Date Received _ 


SA 112 (2012/08) 
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Instructions 


Request to Access Information 


You can access many public body records without making a request under the Freedom of Information and Protection 
of Privacy Act (the FOIP Act). To determine whether you need to make a request under the Act or if you need help 
completing the form, contact the FOIP Coordinator of the public body to which you are making the request. 


About you 

In this part of the form enter: 

e your last name, first name and preferred title, if any; 

e the name of the company or organization you are 
representing, if applicable; 

e your complete mailing address and daytime and evening 
telephone numbers so that the public body can contact 
you about the reguest; 

e a fax number or e-mail address, if any, where 
correspondence may be sent. 


About your reguest 


If you need help to find out what records a public body 
has, contact the FOIP Coordinator for the public body. 


1. What kind of information do you want to access? 
Check general or personal information. 


General information is information other than 
personal information (see below). For example, it 
would include information about a third party. 

Do not include your credit card information in the 
mail or fax. 

e There is an initial fee of $25.00. 

e For a reguest to a government department, make 
the chegue payable to the Government of 
Alberta. 

e For a reguest to a public body that is not a 
government department, please consult with the 
FOIP Coordinator for payment information. 

e The public body provides you with an estimated cost 
before processing begins. 

e If the total cost of processing your request is more 
than $150, you are asked to pay a 50% deposit. 

e The records are provided when the fee is paid in full. 


Personal information is your own personal 
information or the personal information of an 
individual you are entitled to represent. 

e You must provide proof of your identity before 
records containing your personal information are 
released to you. 

e If you are requesting records for another person, you 
must provide proof that you have authority to act for 
that person (e.g. guardianship or trusteeship order, 
power of attorney). 

e There is no initial fee for accessing your own 
personal information. 

e If the cost of photocopying is more than $10, you 
will be notified of the fee. 


Continuing request: This is a single request that is 
processed more than once at predetermined time 
intervals over a period of up to 2 years. 


SA 112 (2012/08) 


e Contact the FOIP Coordinator of the public body if you 
are making a continuing request. 

The initial fee is $50.00. 

You must pay any additional costs as the information 
becomes available. 


2. To which public body are you making your 
request? Enter the name of the public body that you 
believe has the records that you are requesting. 


3. Do you want to receive a copy of the record OR 
examine the record? Check the appropriate box 
indicating whether you want to receive a copy of the 
record or examine the record. 


About the information you want to access 
1. What records do you want to access? 

e Be as specific as possible in describing the records. 

e If you need more space, continue your description on 
a separate sheet of paper and attach it to this request 
form. 

If requesting your own personal information, give: 

e your full name; 

e any other names that you have previously used; and 

e any identifying number that relates to the records, 
such as your employee number, case number or other 
identification number. 

If requesting another person’s information, give: 

e the person’s full name; 

e any other name that person may have used on the 
records; and 

e any identifying numbers for the person, if you know 
them. 

If you are reguesting records for another person, 

you will have to provide proof that you have 

authority to act for that person. 


2. What is the time period of the records? Enter the 
specific dates or date ranges of the records you want 
to access. (e.g. if you want records for the period 
January 1, 2005 to August 31, 2007, enter those dates. 
If you want records from August 2008 to present, enter 
“August 2008 to present.”) 


Your signature 
Sign and date the form. 


Where to send your reguest 

Send your completed form, and initial fee if applicable, to the 
FOIP Coordinator of the public body that has the records you 
wish to access. For contact information, consult the Directory 
of Public Bodies available on the FOIP website at 
foip.alberta.ca. 
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PERFORMANCE OUTCOMES GUIDELINE 


OUR COMMITMENT | 


The City of Airdrie is — to ensuring that there is a sia match between individuals' 
personal values and the City's corporate values. Our recruitment and selection guideline and 
practices guide us in an initial assessment of that match. The first few months of a new hire's 
employment is another opportunity to assess the match. 


Management of performance is an important part of ongoing communication to ensure that 
employees are aware of the expectations of their role and are on track to meet their annual goals. 
This may include coaching, support, encouragement and redirection as required. 


LEARNING COMMITMENT (PROBATION PERIOD) 


The purpose of the Learning Commitment is to allow both the employer and the employee time 
to evaluate the employee's suitability for employment with the City of Airdrie. The learning 
commitment period is six (6) months from the first day of employment. 


It is the responsibility of the immediate team leader and employee to effectively manage the 
learning commitment process. Communication is critical to the success of this process. Therefore, 
it is recommended that the team leader and the employee meet monthly aU. the Learning 
Commitment period. 


At the completion of the Learning Commitment period, an informal review meeting will happen 
to close out the learning commitment and discuss progress. 


Either party may terminate the job arrangement at any time during the Learning Commitment. 


PERFORMANCE PLAN (JOB PROFILE, ANNUAL GOALS AND LEARNING PLAN) 


The purpose of the Performance Plan is to identify what outcomes (product or result) employees 
are expected to deliver during their employment. The Performance Plan becomes a specific 
personal commitment (promise) between the individual and their team leader and co-workers. 
The goals within this Performance Plan will be tied to the department business plan as well as to 
the corporate and council strategic priorities. 


The benefits of a Performance Plan: 


e Role clarity - 

e Enhanced commitment to outcomes rather than activities 

e Create room for personal decision making and personal growth 
e Improve coordination towards business goals 

e Give employees ownership of results 
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e Give employees a way fo measure growth and progress 
e Clarity of expectations and outcomes 
e Personal and professional skill development 


Team leaders are responsible to ensure that employees have completed and/or updated a 
Performance Plan each calendar year or within the first 6 months of employment for new hires. 
Copies of the Job Profile portion of the Performance Plan are to be posted onto MyNet by each 
employee annually. 


INFORMALS/FORMALS 


The Informal is used as a tool for one-on-one dialogue between an employee and their team 
leader. It is the responsibility of both the team leader and team member to schedule monthly 
informals. At the end of every quarter, documented Quarterly Review comments are to be 
completed and attached to the annual Formal. 


Formal meetings are an opportunity to review/evaluate the past year's performance and 
accomplishments as set out in the Performance Plan. Generally consensus is reached between 
the employee and team leader as fo the final document to be placed on the employee's 
personnel file. 


It is the responsibility of the team leader to ensure a Formal is conducted annually with each 
employee. Once the Formal review is completed, it is to be sent to Human Resources along with 
the current Performance Plan and Quarterly Reviews. 


CORRECTIVE ACTION 


Relationships begin with a committed partnership on the part of the employee and the team 
leader to ensure the success of both the employee and the City. When improvement is required, 
the corrective action process is used to aid learning, provide redirection and help achieve the 
desired outcomes. Human Resources is consulted in all steps of the process and is present in all 
steps beyond Step 1. 


Communication during this process is to be clear and definitive and the team leader and 
employee should check to ensure the expectations and behaviors required during each 
conversation are clearly understood and agreed to. 


These steps ensure that Corrective Action is applied consistently and fairly to all City employees. 
Depending on the seriousness of a situation, any and all steps may be skipped. 


STEP 1: Problem Solving Session/Coaching 


e The team leader will discuss the behavior or action needing improvement with the 
employee and clarify expectations. A plan of action and a timeline for improvement will 
be discussed and agreed to. 
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If job expectations are still not met, the team leader will document further coaching sessions and 
will advise the employee accordingly. 


If the situation progresses beyond coaching, the team leader will consult with Human Resources 
prior to proceeding to Step 2. 


STEP 2: Written Reminder 


Failing improvement, the employee will be issued a Written Reminder clearly defining the 
expectations. This Written Reminder should include: 


e Examples of the inappropriate action/ behavior and its impact 
e The expected action, behavior and standards 

e Resources required 

e Time frames 


In addition to these steps, the employee is to be made aware that failure fo meet the required 
changes will lead to further consequences, Up fo and including dismissal. 


The original Written Reminder will be given to the employee and a copy will go to the employee's 
personnel file in Human Resources. 


STEP 3: Decision Making Leave 


Where required, the employee may be given a ‘Decision Making Leave’ with or without pay. This 
step allows the employee time off to decide whether or not they wish to continue employment 
with the City. If the employee makes the decision to continue employment with the City, they will 
be required to provide a written action plan outlining how they will correct the behaviors or 
actions identified. 


STEP 4: Dismissal 


If, after a reasonable period of time, the employee has failed to correct the problem, it may be 
necessary to terminate employment. Approval is required from the City Manager or designate, 
in consultation with the team leader and Human Resources. 


A notice period, payment of wages in-lieu-of-notice, or a combination thereof shall not be paid 
to the employee if: 


e The employee has been employed with the City for less than three (3) months 
e The employee is dismissed for “just cause” 
e The employee voluntarily terminates his/her employment 


Any employee who is absent for three consecutive days without notification or written 
authorization for a leave will be considered to have forfeited their position with the City unless their 
immediate team leader is notified prior to the end of the three day period and proper 
documentation, if required, is supplied. 
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Administrative Policy 
Computer Use 


gas) OPPORTUNITY 


Issued: February 27, 2014 


Information Technology Department 
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City of Airdrie 
Administrative Policy - Computer Use 


Effective Date: ENTER DATE HERE 
Approved By: City Council 
Approved On: ENTER DATE HERE Resolution#: ENTER # HERE 


1. General Provision 
1.1. Purpose 


1.1.1. To ensure all End-Users are provided the necessary information to outlining the 
permissible and non-permissible actions and uses of a computer system. 


1.1.2. To ensure each End User with access to a computer system understands they are 
responsible and accountable for the security and integrity of the City of Airdrie's 
corporate data and systems. 


1.1.3. To protect the interests and obligations of the City of Airdrie. 
1.2. Scope 
This policy includes any individual who has or is responsible for a Network login account used 


on any computer system that has access to the City of Airdrie Network, or stores any non-public 
City of Airdrie information. 


1.3. Other Policies 


All City policies and procedures apply to employees' conduct on the Internet, specifically, but 
not exclusively, relating to: intellectual property, confidentiality, City information dissemination, 
standards of conduct, misuse of City resources, anti-harassment, Freedom of Information and 
protection of Privacy Acts (FOIP) and information and data security. 


1.4. Employee Liability 


Employees are individually liable for damages incurred as a result of violating this policy. 
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2. Definitions 


2.1 Authorized Employee — Staff tasked to protect City of Airdrie assets and Computer 
Systems. 

2.2 BYOD (Bring Your Own Device) — Permitting staff to bring personally owned mobile 
devices (laptops, tablets, and smart phones) to their workplace, and to use those 
devices to access privileged City information and applications. 

2.3 City — City of Airdrie. 

2.4 Computer Systems — A City owned system of one or more computers and associated 
software with common storage. The computer system can be physical or virtual. 

2.5 Computer Viruses/Malware - Malicious computer programs written to damage the 
program files in a computer, reputation or effect on ecommerce. 

2.6 End-User — Any person operating a computer system. 

2 Hardware — The physical electronic device. The Hardware can be owned by the City, 
End-User or a consultant. 

2.9 Material — Any visual, textual, auditory, file page graphic or other entity. 

2.9 Network — A collection of computers and other Hardware interconnected by 
communication channels that allow sharing of resources and information. 

2.10 Software — A program installed on a piece of Hardware. 

2.11 USB Drive — A removable external storage device. 

2.12  VDI - Virtual Desktop Infrastructure. A desktop-centric service that hosts user desktop 
environments on remote servers. 
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3. Privacy, Rights and Monitoring 


3.1. 


Privacy 


Employees are given access to the computer resources of the City to assist them in the 
performance of their jobs. Employees that use City-owned computer systems for personal use 
of any form should not have any expectation of privacy in anything they create, store, send or 
receive. 


3.2. 


3.2.1. 


3.2.2. 


3.3. 


Waiver of Privacy Rights 


Employees expressly waive any right of privacy and ownership in anything they create, 
store, send or receive on a City owned Computer System. Employees consent to 
allowing Authorized Employees to access and review all Materials the employees create, 
send, store, or receive on a Computer System. The use of passwords or other security 
measures does not in any way diminish the City’s right to access Materials on its 
Computer System or protect any privacy rights of employees who create the materials 
on the computer system. 


The City of Airdrie will comply with reasonable requests from law enforcement for logs, 


diaries, archives, or files on Computer Systems and e-mail activities. The release of 
information must be in compliance with FOIP legislation. 


Monitoring of Computer Usage 


The City has the right and duty to protect the Computer Systems and monitor all computer 
related activity by employees including, but not limited to, monitoring sites visited by employees 
on the Internet, search engine lookups, monitoring chat groups or social networking sites, 
reviewing material downloaded/uploaded by employees to the Internet or cloud-based services 
and reviewing e-mail sent and received by employees. 
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4. Acceptable Computer Uses 


4.1. The City recognizes the importance and advantages of Computer Systems and 
associated technologies. The City promotes the use of these technologies by providing 
resources that enable employees to use and access these technologies. Employees are 
encouraged to use City Computer Systems and associated technologies to: 


a) Further the City’s mission; 

b) Support goals and objectives of the City; 

c) Support the provision of high quality customer service; 

d) Promote partnership and community involvement with the citizens of Airdrie, other 
government agencies, community organizations and businesses; 

e) Provide information related to the activities and services offered by the City; 

f) Support direct job-related purposes; 

g) Increase productivity; 

h) Increase professional growth. 

i) Maintain the integrity of the City. 


4.2. _ City computer systems and associated technologies are provided for business purposes. 
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9. Unacceptable Computer Uses 


Use of City Computer Systems, Networks, and Internet access is a privilege granted by 
management and may be revoked at any time for inappropriate conduct including, but not 
limited to: 


a) Using someone else’s computer system when they are logged in; 

b) Sharing of logins and passwords; 

c) Consuming computer system resources (drive space, printer paper, etc.) for personal 
use; 

d) Personal gain; 

e) Sending chain letters, music, videos, animations or joke e-mails; 

f) Engaging in private or personal business activities; 

g) Misrepresenting oneself or the City; 

h) Engaging in unlawful or malicious activities; 

i) Using abusive, profane, threatening, racist, sexist, or otherwise objectionable language 
in either public or private messages; | 

j) Sending or accessing racist, sexist, threatening, retaliatory profane, discriminatory, 
sexually harassing, offensive, pornographic or otherwise objectionable or illegal Material; 

k) Initiating or participating in cyber-bullying; 

l) Causing congestion, disruption, disablement, alteration, or impairment of City Networks 
or systems; 

m) Copying and/or transmitting documents in violation of copyrights laws; 

n) Copying and/or transmitting documents or information in violation with Provincial or 
Federal Freedom of Information and Privacy (FOIP) laws or FOIP legislation; 

o) Downloading and/or installing Software or using web based Software as a service 
application without the prior approval from IT; 

p) Improperly downloading files that contain viruses, which may compromise City 
information systems and databases; 

q) Deliberately propagating viruses or other code or files designed to disrupt, disable, 
impair, or otherwise harm the City's Networks or systems or those of any other individual 
or entity; 

r) Downloading non-work related or unauthorized Software; 

s) Using recreational games; 

t) Defeating or attempting to defeat security restrictions on City systems and applications; 

u) Sending emails to solicit or sell products or services; 

v) Moving a City-owned workstation without the approval or assistance of IT. 

w) Utilizing the personal hot spot of a City mobile device to circumvent security policies or 
filters; 

x) Using cloud-based personal Network storage or peer-to-peer services; 

y) Using services that facilitate synchronization of data from a City QUE system or 
mobile device to the cloud; 
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6. System Access 


Access to the City's Computer Systems, Network, Hardware and Software application systems, 
is restricted to Authorized Employees of the City and authorized service providers. 


6.1. Usernames and Passwords 


6.1.1. Access to the City’s corporate Computer Systems is controlled by usernames and 
passwords which further control access to specific systems, files and directories. Each 
End-User will be provided with a username and password, which will allow access to the 
Network. Each End-User is accountable for all actions performed with their login 
credentials. 


6.1.2. All passwords are to be treated as sensitive, confidential City of Airdrie information. All 
passwords must conform to the guidelines described in the City of Airdrie Password 
Procedures. (found on MyNet) 


6.1.3. Individual or personal login names and passwords are not to be shared with anyone, 
including other City of Airdrie personnel. 


6.1.4. The City Manager, Directors, Managers, Team Leaders and IT Team Leaders are 
permitted to reguest and retain the passwords of employees to gain access to stored 
data and email if reguired in the event the employee is absent. 


6.1.5. Employee passwords shall be changed periodically (every 90 days) to maintain an 
effective deterrent against unauthorized use. 
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7. System Security 


7.1. Sites Blocked 


Protection of City of Airdrie confidential information is further enforced using an Internet 
reputation system. This system protects the City Network by preventing low reputation sites or 
sites that potentially contain threatening content from being accessible. Additional sites can be 
added at the discretion of Team Leaders or Directors. 


7.2. Emails Blocked 


The City of Airdrie uses a system that blocks incoming and outgoing spam/malware emails and 
blocks those that are considered harmful. On occasion, business emails may get blocked. 
. Business emails will be released and business email addresses will be added to the safe list 
after an investigation to determine the reason they were blocked. Personal emails that are 
blocked will only be released if they do not contain jokes, use of profanity, obscene, suggestive 
images or offensive graphical images and are not spam. 


7.3. System Protection 


Staff is encouraged to request IT assistance with the physical security of the Hardware and 
protection of Software systems when End-Users are working in the field. The scheduling and 
level of protection of any City computer Hardware or Software system shall be at the direction of 
the Team Leader. 
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8. Data and Information Security 


8.1.1. It is the full responsibility of the employee to ensure that information of a sensitive nature 
or is classified as personal and/or confidential is handled in accordance with appropriate 
City policies, procedures guidelines or provincia! and federal legislation. 


8.1.2. An End-User shall not access data or information that is of a sensitive nature, or is 
classified as personal and/or confidential without proper authorization. 


8.1.3. Data and information containing personal information must be managed appropriately 
under FOIP legislation and the data must not be removed from corporate systems. |f 
this data must be transported or transmitted, the data shall be encrypted to prevent 
unauthorized access to the data. 


8.1.4. In the event data or information containing personal information is lost or leaves the 
controlled possession of the City of Airdrie, its employees or authorized service 
providers, the FOIP Coordinator must be advised immediately to determine whether the 
Privacy Commissioner and affected parties should be notified. 
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9. Computer Virus and Malware Protection 


9.1. The City provides virus and malware protection as part of its framework of defense 
mechanisms against viruses and other forms of system breaches. The City does this 
because desktop and Network computers are susceptible to infection by Computer 
Viruses and Malware that can cause unauthorized system access, system malfunction 
and loss of data. 

9.2. If a suspicious activity is detected, or it is known that an employee is deliberately 
spreading system related viruses and malware, contact a Team Leader and the IT 
Service Desk immediately. 

9.3. Disciplinary action including charges shall be taken against anyone caught knowingly 
spreading Computer Viruses. 

9.4. Employees shall follow these guidelines to prevent the spread of Computer Viruses: 

a) Suspected email messages or Internet sites that end-users feel are unsafe should not be 
accessed and reported to IT Service Desk; 

b) Do not allow any non-City owned USB Drives to be inserted or used in any City of Airdrie 
computer without the approval of IT. 

c) Do not use software obtained from outside sources (i.e. bulletin boards) that are not 
authorized for City use. 

d) Downloading or sharing of Software programs from the Internet or any non-City 
computer is prohibited unless authorized by the IT Team Leaders. 

e) Do not leave the computer unsecured or unattended for a prolonged period of time. 

f) USB Drives are scanned real time for Computer Viruses and Malware. 

10. Employee Termination 

10.1. In the event a City of Airdrie employee terminates or is suspended from their 
employment with the City, their Team Leader or delegate is responsible for notifying IT 
immediately to ensure the Citys computer Hardware, electronic information and 
Software programs are protected from unauthorized or malicious activity. 

10.2. Team Leaders are responsible for sending a Remove User request as soon as an 
employee has been terminated or left the organization. 
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Software 


The IT Team Leaders shall review all Software purchases and maintenance agreements 


to ensure the needs and interests of the City are protected. (from the technical 


perspective) 

Only purchased and approved Software licensed and owned by the City is to be installed 
on City computer systems. When unauthorized Software is discovered it will be 
immediately removed and the End-Users Team Leader will be notified. 


IT shall provide Software support and technical assistance for all approved Enterprise 
Software products. 


All Software installations and removals are to be completed by IT. 


No employee may create, use, or distribute copies of such Software that are not in 
compliance with the license agreements for the Software. 


Remote Access 


. This City of Airdrie provides the capabilities to access City’s Computer Systems from remote 
locations providing these locations have Internet access. To obtain remote access, employees 
must contact their Team Leader who will determine if remote access is appropriate. If 
appropriate, the Team Leader will collaborate with IT and the employee to obtain remote access 
and associated training. 


13. Computer Training 

13.1. All staff should possess a basic understanding of how to use computer Hardware and 
have an understanding of basic security practices. Staff should also have some 
competence using Microsoft Office products. 

13.2. It is not the responsibility of IT to be proficient and capable of training staff on all desktop 
software. 

13.3. It is the responsibility of the departments Team Leaders to determine and fund staff 
technology training. 

14. Mobile Device Use 

141 Laptops, Tablets and Smartphones 
a) A City owned mobile device is not to be used to transmit or receive information that 

is out of compliance with the Computer Use Policy. 
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b) A City-owned mobile device is not to be used to circumvent established filters or 
policies within the environment to allow access to or the transmission of City 
information. 

c) A City-owned mobile device is not to be shared with non-City staff. 


Bring Your Own Device (BYOD) 


a) Devices will require antivirus Software and the latest virus definitions. 

b) Devices will require the latest operating system upgrades, patches and security 
updates. 

c) Devices will not be permitted to copy City owned information to the device. 

d) Devices will utilize VDI to unify the end users’ desktop. 


Policy Updates 


This policy shall be updated on an as needed basis and is subject to change at any time. 
Team Leaders are responsible to ensure all City employees accessing a City Computer 
System understand and comply with this policy. City employees are encouraged to 
contact their Team Leaders or an IT Team Leader regarding questions about this policy. 


Team Leaders are responsible for ensuring that any violation of this policy is handled in 


a fair and consistent manner. Team Leaders shall also act in good faith to ensure this 
policy is administered fairly and consistently. 


Respecting the Policy 


Any person, subject to this policy, who fails to comply with the provisions as set out within this 
policy or any amendment thereto, shall be subject to the appropriate disciplinary action in 
accordance with the City of Airdrie Performance Outcomes Guidelines (this document can be 
found on MyNet). 
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CITY OF AIRDRIE 
Administrative Policy: 
INFORMATION GOVERNANCE AND MANAGEMENT (IGM) POLICY 


Effective Date: July 31, 2014 Revision Date: October 24, 2017 
Approved By: Senior Leadership Team 

Approved On: July 31, 2014 Resolution #: 

PURPOSE: 


The purpose of this policy is to provide a framework to ensure consistent and cost-effective 
management of physical and electronic information within the City of Airdrie throughout its life 
cycle. The life cycle includes the creation, maintenance, use, storage and disposition. 
Compliance with this policy will ensure the reliability and accuracy of information and that 
information remains accessible over time. | 


SCOPE: 


This policy applies to all employees, contractors, volunteers, and elected officials of the City of 
Airdrie and includes information in any and all formats, created or received in the course of 
business regardless of the device used to do so. The policy also applies to all business 
information systems used to create, manage, and store information. 


DEFINITIONS: 

ə Access: The ability, right, and permission to use or the general availability of information. It 
includes both disclosure of information under the Freedom of Information and Protection of 
Privacy Act (FOIP) as a result of a request and the routine release of information that is 
available to the public or to an individual. 


e Active Information: Information that is in current use and needs to be accessed frequently or 
on a regular basis. 


e Authentic: Not false or copied. Having origin of unquestionable evidence. 


e Business Information Systems: Information technology resources used to meet relevant 
organizational requirements. Includes all databases. 


e City: The corporation of the City of Airdrie. 
e City Manager: The Chief Administrative Officer or his delegate. 


e Corporate Information: All information of every City department/business unit, board, 
commission, and committee that is evidence of or a part of a transaction or business decision. 
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e Disposition: The disposal of information no longer needed for day-to-day operations through 
destruction, secure destruction, or transfer of information of enduring value to archives. 


e Inactive information: Information that is accessed less frequently and must be kept for a 
certain length of time to meet statutory, fiscal, or other requirements. 


e Indexed: A manual or automated listing arranged differently from a related record series or 
system to speed retrieval of relevant information. 


e Information: All forms of recorded information that is in the custody and control of the City, 
which includes but is not limited to documents, hand written notes, draft documents, voice mail, 
vouchers, drawings, letters, papers, email, books, maps, photographs, calendars, and post-it 
notes. 


e Life Cycle: The stages of the life cycle of information include: 


Creation — planning, collecting, creating, or generating information; 
Maintenance — organizing or retrieving; 

Use — using, accessing, or transmitting; 

Storage — storing and protecting; and 

Disposition — destroying or transferring to archives. 


Oo O O © 


e Information Management: The application of systematic control to the life cycle of all forms of 
recorded information produced by the City in the conduct of its operations as dictated by 
information governance policies. 


e Information Governance and Management Program: A planned, coordinated set of policies, 
procedures, standards, controls and metrics that specify how the City’s information is managed 
as a business asset. Information governance provides structure to the strategy of information 
management. 


e Retention Period: The total length of time information must be kept before final disposition is 
implemented. Retention periods are determined by business use, legislation, and/or a 
combination thereof. Information shall not be copied and/or retained after the retention 
period has expired. 


e Retention Schedule: The timetable that identifies the retention period during which information 
must be retained before disposition. 


e Transaction: The act of conducting or carrying out business, negotiations, or plans. 


e Transitory Information: Information in any format that is required for a limited time to complete a 
routine action, is used in the preparation of final documents, or is retained as informational or 
convenience copies by business units or individuals. 
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POLICY: 


Information is a corporate asset. The information of the City is an important source of 
administrative, fiscal, legal, evidential, and historical information. It is vital to the City in its 
current and future operations for the purpose of accountability, for an awareness and 
understanding of its history, in order to maintain an authentic and reliable evidence of its 
business decisions and transactions, and for strategic planning purposes. Information is the 
corporate memory of the organization. 


The IGM Program functions in accordance with operational needs, fiscal/legal requirements, 
government regulations, and for historical purposes. 


This policy provides for the requirements that must be met for the information of the City to be 
considered authentic and reliable evidence of the activity of the organization. It extends to 
assisting with the determination of requirements for systems, technologies and processes that 
touch information in any way. 


Creating information: 


Information, regardless of medium, must be created and captured by the employees of the City 
in accordance with this policy. Employees are responsible for knowing what information should 
be created in their role. Information created must provide a reliable and accurate account of 
business decisions, actions, and transactions. This includes all necessary information to 
support business needs including key information needed to capture the business context. 


Information will be maintained in an approved library or system within an approved structure, 
classification system, and retention schedule using appropriate naming conventions for files and 
folders. 


Maintaining information: 


Information has a life cycle that runs from its creation and active use to its final disposition at the 
end of an approved retention period. It must be maintained in a way that ensures it is accessible 
and secure throughout its life cycle. Information must be scheduled for disposition according to 
the Retention Schedule. 


Regular confidential disposal of transitory information is the responsibility of all employees in 
accordance with the Transitory Information Guidelines. 


All information, regardless of medium, is subject to FOIP and will be managed consistent with 
FOIP guidelines and industry best practices throughout its life cycle as part of the management 
of recorded information. 


All corporate information must be stored in approved libraries. Information transferred outside 
of the Citys physical environment must be protected through information technology best 
practices. 


Access to information: 
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The City complies with FOIP regardless of whether the reguest for information is within or 
outside of the Act. The City supports the principle of access to corporate information and 
information to those who reguire it to perform their duties, deliver services in an effective and 
efficient manner, and to facilitate reasonable public access to information in its custody or 
control. 


Disclosures of information under FOIP or informal reguests for information are processed 
according to the provisions of FOIP or within the spirit of that legislation. The City and its 
employees make every reasonable effort to assist and to respond to reguestors openly, 
accurately, and completely. 


Transferring Physical Information to IGM 


Information becomes inactive when it is no longer needed for freguent reference. When no 
longer in active use, physical business information will be transferred by City business units to 
IGM for the remainder of the retention period. 


Retention and Disposition of Information 


Keeping information longer than necessary or not long enough is a liability to the City and 
complicates compliance with the FOIP Act and other legislation. 


IGM, in conjunction with the business unit, is responsible for the disposition of information. The 
Retention Schedule sets out the appropriate periods that information must be retained. When 
information is no longer reguired to be kept, its destruction must be authorized and documented 
and disposal must be performed using approved methods according to the City's Disposition 
Process. 


Information that is to be retained permanently must be managed if the information is to remain 
viable, authentic, and accessible and in accordance with the City's Long Term Digital 
Preservation Standard. 


Legal Holds 
The City of Airdrie has a duty to preserve relevant information whenever litigation or a FOIP 
reguest is reasonably anticipated, threatened or pending. Steps must be taken to suspend the 


disposal of all information in all formats, including transitory, in accordance with the Legal Hold 
Process. This duty arises regardless of whether the City is the initiator or the object of litigation. 


City Manager 


City Clerk 
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The City of Airdrie creates, collects and processes a vast amount of information in multiple formats 
every day. The City needs information to be readily available to all those who require it to support 
effective decision making while at the same time protecting the integrity, confidentiality and value of 
the asset. The Information Security Classification applies to information in all formats, created or 
received in the course of business. 


Why is security classification important: 


Wer 


og 


There are several reasons why the City should be concerned about information security classification. 
These include: 


e Supporting routine disclosure and active dissemination: Security classification of information 
assets is a critical component in identifying and facilitating the disclosure of information to the 
public. It can also help identify information that needs to be protected but might be inter-filed 
with or combined with unrestricted information. 


e Business efficiency and effectiveness: In order to make effective and timely business 
decisions, information needs to be available for City employees. Barriers to collaboration or 
access to information result in duplication/copying of information and contributes to 
redundant, outdated and trivial information. 


e Protection of personal information: The Freedom of Information and Protection of Privacy Act 
(FOIP) governs the collection, use and disclosure of personal information. The FOIP Act also 
governs the management of personal information — its protection, retention, and accuracy. 
Security standards support the effective application of the Act in the conduct of day-to-day 
business. 


e Protecting confidential information from unauthorized access: in the normal operation of the 
City, certain information must remain confidential. Applying proper security classification and 
practices can safeguard against unauthorized access to confidential information. 


e Protecting intellectual property: Intellectual property investments need to be protected to 
benefit the citizens of Airdrie. Appropriate security practices are needed to ensure an 
adeguate level of protection. 
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Four criteria are the basis for deciding the security and access requirements for data and information: 


e Availability: employees have access to and can find and use information when required; 
e Integrity: data and information is complete, and only authorized changes are made to it; 
e Confidentiality: information is accessed by authorized individuals, entities, or processes; 


e Value: intellectual property is protected, as needed. 


Information Security Classification Internal Use 1 
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Regardless of security classification, information that is identified as required for an access to 


information request under the FOIP Act must be searched, located, and provided. Insome 
circumstances, it may be necessary to apply additional security requirements due to acts and 


regulations. Legislation alone does not set the security classification level of information. 


Legislative Services, Information Governance and Management and Information Technology will work 


with areas if any special considerations are identified with regard to information that is highly 


sensitive. 


The secu rity classification standard for information assets at the City of Airdrie consists of four 


categories. These categories, with a description and examples of (including but not limited to) the 
types of information that might be found in that category, are outlined in the tables below. Please 


note that these categories reflect what can be seen by whom and does not broaden the ability for who 


can create, amend or delete information. 


Public 


Internal Use 


Information that is available to 
the general public or deemed 
public by legislation or through 
routine disclosure. Available to 
the public, all employees, 
volunteers, contractors, sub- 


contractors and agents. 


Information that is sensitive 
outside the City and needs to be 
protected. This information is 
available to employees, 
volunteers, contractors, sub- 
contractors and agents for 
business-related purposes and is 
consistent with FOIP. 


Job postings 

Council Agenda and Minutes 
Board Agenda and Minutes 
News or media releases 
Council Policies 

Council approved budgets 
Anything typically found on the 
website 


Policy interpretation 

Staff meeting agendas and 
minutes 

Draft request for proposals 
Business information 
Applications 

Planning documents 

Internal policies and procedures 
(excluding those published on the 
web) 

Training manuals and 
documentation 

Staff newsletters 

Organization charts 

Project charters, status reports 
Unpublished financial reports 
Completed budgets awaiting 
Council Budget Committee 
and/or Council approval 


Little or no impact 


Minimal 
inconvenience if not 
available 

Disclosure would not 
result in any loss or 
harm to an individual 
or the City (that is, no 
legal effect) 


Unfair competitive 
advantage 

Disruption to business 
if not available 
Unauthorized 
disclosure, alteration 
or destruction could 
result in low level risk 
to an individual or the 
City 


Information Security Classification Internal Use 2 
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Information Security Classification Standard 


Confidential 


Restricted 


Information that is sensitive 
within the City of Airdrie 
(includes highly sensitive 
personal information) and is 
available only to named 


individuals or a specific position, 


function, group or role. 


Information that is highly 
sensitive and available only to 
specific, named individuals or 
specific positions. If 
compromised could cause 
severe harm to an individual or 
the City. 


Awarded contracts 
Business continuity plans 


Payroll and Benefits information 
Personnel information 
Individual Health and Safety 
information 

3'd party business information 
submitted in confidence 
Information covered by non- 
disclosure / confidentiality 
agreements 

Passwords 

Information collected as part of 
investigations 

Incident reports 

Personal medical/disability 
information (benefits 
information) 

Enforcement information 
Specific FOIP requests 


In camera minutes 


Contracts where confidentiality is 


specifically noted. 


Criminal records checks 
Criminal investigations 

High risk infrastructure maps 
IP addresses 


Loss of personal or 
individual privacy 
Loss of trade secrets 
or intellectual 
property 

Loss of reputation 
Loss of competitive 
advantage 

Financial loss 
Unauthorized 
disclosure, alteration 
or inaccessibility 
would have an 
adverse effect on the 
City, employees, 
volunteers, 
contractors, 
customers 


Loss of life 

Loss of public safety 
Significant financial 
loss 

Significant damage 
Compromise of the 
legal system 
Sabotage or terrorism 
Unauthorized 
disclosure, alteration 
or inaccessibility 
would have a severe 
effect on the City, 
employees, 
volunteers, 
contractors, 
customers 
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Purpose 

In addition to applying a classification level to information, an important part of information 
classification involves identifying the access/security, labelling and storage controls to be applied to 
each level. The Information Security Handling Process provides the various technical and organizational 
controls required to ensure appropriate security practices are applied in the management of the City’s 
information assets. Appropriate handling supports customer service, efficient operations and ensures 
that integrity is maintained. 


This Process applies to all information assets in all formats, created or received in the course of 
business and applied in accordance with the Information Security Classification Standard. 

When accessing data and information that is classified as Internal Use, Confidential or Restricted, 
auditing and tracking procedures are required to ensure authorized access. 


Access Methods 


Public e Access open to the public and e None 

all employees, contractors, 
sub-contractors, and agents 

e Can be published if it is of 
value/interest to the public 

e Determination to publish 
material is made by the 
business unit 


Internal Use 


Confidential 


Restricted 


Authorized access (employees, 
contractors, sub-contractors 
and agents) for business 
related purposes 

Access limited to individuals in 
a specific position, function, 
group or role 


Access limited to named 
individuals or specific position 


Periodic audits to show 
protection is, in fact, occurring 


Permission based on employee 
position or contractor, sub- 
contractor or agent 
relationship 

Log of access/actions 

Periodic audits of adequate 
protection 


All access or actions will be 
logged and subject to 
validation processes as 
appropriate 


Information Security Classification Internal Use 1 
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Information Governance and Management 
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Cloud computing refers to the delivery of computer services (e.g., servers, databases, applications and 
more) over the Internet (“the cloud”). Cloud services companies (“cloud providers”) are increasing 
rapidly, offering solutions for businesses and individuals alike. There are many compelling reasons to 
consider cloud-based solutions within organizations as they can enable agile, flexible and cost-effective 
IT services. However, there are also some risks and challenges with cloud based solutions, including, 
but not limited to, compliance with privacy legislation. 


The City’s goal is to enable effective governance while also ensuring compliance with privacy legislation. 
As a risk mitigation strategy, the City has developed this Cloud Computing Standard. The purpose of this 
standard is to set out how the City of Airdrie’s information must be preserved when stored, used or 
transmitted by a third-party cloud provider. 


This standard applies to all employees using technology to fulfill their duties for the City of Airdrie. All 
information technology applications and services are subject to this standard, regardless of their use or 
physical location. 
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1. All City of Airdrie Information that contains “personal information” (as defined by Alberta’s 
Freedom of Information and Protection of Privacy Act) or that is classified as, Confidential or 
Restricted in accordance with the City of Airdrie’s Information Security Classification Standard 
must be stored in City of Airdrie approved computing facilities located within the geographic 
boundaries of Canada. Those cloud providers that will hold personal information as described 
above will be given priority consideration if they provide certification evidence of compliance 
with the International Organization of Standardization ISO/IEC: 27018:2014 Code of Practice for 
Protection of Personally identifiable Information in Public Clouds. | 

2. City of Airdrie information classified as Public or Internal Use can be stored with a City of Airdrie 
approved cloud provider outside the geographic boundaries of Canada. 

3. All cloud providers are expected to provide documentation/evidence of information security 
management processes with priority consideration given to applications or services in 

compliance with the ISO/IEC 27001 Information Security Management standard. 

4. Whenin "transit", within Canada or internationally, all information (Internal Use, Confidential or 
Restricted) will be encrypted. 

5. City of Airdrie employees will not utilize personal (free or fee based) cloud computing services 
such as Dropbox, Box, Amazon Cloud Drive, Google Drive, or any similar solutions for the storage 
or transmittal of any City of Airdrie information. 

6. An Information Governance and Management Business Systems Assessment and Privacy Impact 
Assessment must be completed for all cloud providers. Even though a cloud provider may be 
able to comply with the data residency requirements of being within Canada, a cloud provider 
may not be approved if they are not able to adequately comply with the conditions set out in 
the Business System Assessment, Privacy Impact Assessment or with the requirements specified 
below for Cloud provider service agreements. 

7. Service Agreements will exist with all cloud services providers providing applications or services. 
The agreements must include, at minimum, the following requirements: 
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a. Clear confidentiality, integrity and availability assurances including the 
handling/treatment of confidential or sensitive information in accordance with the 
Province of Alberta’s Freedom of Information and Protection of Privacy Act (FOIP). 

b. Assurances regarding data residency remaining in Canada including secondary or 

subsequent backups. 

Employee security awareness and training. 

Limitations on information collection, use and disclosure. 

Information ownership must remain solely with the City of Airdrie. 

Vulnerability management requirements including periodic vulnerability assessments 

and penetration testing. | 

g. Suitability requirements on the third party, including the provision of independent 
audits and audit attestations on information security controls. | 

h. When credit card data is involved, the requirement to demonstrate ongoing compliance 
as a service provider to the Payment Card Industry Data Security Standard. 

i. Information Security incident response, management and notification requirements. 

j. Limits and requirements on subcontracting. 

k. Encryption methods being utilized when information is at rest and when in transit. 

l. Parameters for restricting access to personal information including utilization of 
protected audit trails that will be available to the City of Airdrie. 

m. Parameters regarding communications in the event of a breach. 

Business continuity procedures in the event of an outage. 

Restrictions on the cloud provider (or a third-party) to access, use or analyze the 

information for its own purposes, including but not limited to, advertising purposes. 

p. Protocols related to granting access to foreign courts, government agencies and law 
enforcement. 

q. Provisions governing the return (including methods and formats for transfer) and secure 
destruction of information in the cloud provider’s possession upon contract | 
termination. 
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The following policies, standards and processes are related or provide additional direction and should 
also be reviewed: 


e |T Computer Use Policy 

e Information Governance and Management Policy 

e Information Security Classification Standard 

e Information Security Classification Handling Process 
e IGM Business System Assessment 


The IGM Program team (which includes members from IGM, IT and Legislative Services) will review this 
standard every two years from the date of the original approval. 


The Information Governance and Management Steering Committee (IGMSC) is responsible for approval 
of this standard. 
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References ATIA-19(0) 


This standard draws upon the research, standards, efforts and publications of the following 
organizations: 


e Government of Canada IT Policy Implementation Notice 2017-02 Direction of Electronic Data 
Residency 


e Government of Canada Cloud Adoption Strategy 
e The Government of Nova Scotia Bill No.19 Personal Information International Disclosure 


Protection Act, 2006 

e The Government of British Columbia Bill 73 — the Freedom of Information and Protection of 
Privacy Amendment Act, 2004 

e Government of Alberta Cloud Computing Reference Architecture Standard A000064 

e US Government NIST Cloud Computing Reference Architecture 


Original Draft 


Incorporated feedback from Jay Stoudt, Manager, Information 
Technology 
Incorporated feedback from Sharon Pollyck, Director, CAO Office 


Incorporated feedback from Jelena Maric, Team Lead — 
Procurement, Insurance and Risk 
Issued for review and endorsement by IGMSC 


O 
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The table below provides the labeling techniques for various types of information in all forms. The 
actual labeling procedure will vary depending on the media type in which the data and information is 
stored. 


Labeling Methods 


i 
l| 


ES 
x 


ROSES) RIRA Seay UY S S 2 
uu MN e No labelling requirements e No labelling requirements 


Internal Use e For information received from e Identify security classification in 
external sources, documents do document metadata according to 
not require specific labelling and Minimum Metadata Standard 
are deemed to be Internal Use e Information Security 

unless otherwise classified Classification will be visible in 

For hard-copy documents footer of all pages of electronic 
created internally, Internal Use documents 
will be in the footer of all 
documents | 


Identify security classification in 
document metadata according to 
Minimum Metadata Standard 

e Information Security 
Classification will be visible in 
footer of all pages of electronic 
documents 

e The subject line of emails will 

contain “Confidential” as part of 

the subject line 


For information received from 
external sources, documents will 
be ink-stamped with 
Confidential on the first page in 
footer if possible 

Information received from 
external sources that has been 
classified will remain 
Confidential or higher as 
applicable 
For hard-copy documents 
created internally, Confidential 
will be in the footer of all 
documents 
Hard media such as CDs, DVDs, 
and USB drives will be identified 
as Confidential with the 
application of adhesive labels 

For hard media created 

internally, Confidential will also 

be displayed when the 
information stored on the media 
is accessed 

For information received from 

external sources, documents will 

be ink-stamped with Restricted 
on the first page in footer if 


Confidential 


Identify security classification in 
document metadata according to 
the Minimum Metadata Standard 
Information Security 


Restricted 


Information Security Classification Internal Use 2 
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possible 

Information received from 
external sources that has been 
classified will remain 
Confidential or higher as 
applicable 

For hard-copy documents 
created internally, Restricted will 
be in the footer of all documents 
Hard media such as CDs, DVDs, 
and USB drives will be identified 
as Restricted with the 
application of adhesive labels 
For hard media created 
internally, Restricted will also be 
displayed when the information 
stored on the media is accessed 
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Classification will be visible in 
footer of all pages of electronic 
documents 

The subject line of emails will 
contain “Restricted” as part of 
the subject line 


Depending on the security classification, data and information will need different types of storage 
processes to ensure that the availability, confidentiality, integrity and value of the data and information 


are protected. Backups require the same care as originals. 
Storage Methods 


Store within City of Airdrie 
facilities or buildings 
Keep out of public view 


Confidential Secure location with limited 
access 
Clean desk 

Restricted Stored in highly secure location 
with access tracking 
Clean desk 
Audit trail for all access (e.g., 
access report from locked file 
room; signatures) 
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No special storage reguirements 
Regular back-ups to ensure 
availability and integrity 


All media under physical and/or 
logical access control e.glimited 
system administration access, 
monitored connections to 
networks, system files and data) 


All media under physical and/or 
logical access control of 
confidential zone (e.g., 
authorized access and 
authenticated access) 


All media under physical and/or 
logical access control of 
restricted zone (e.g., single or 
double authentication, 
encrypted data, audit and 
monitoring) 


Information Governance and Management 
Information Security Handling Process 
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special protection procedures are necessary as follows: 


Transmission Methods 


Sealed envelope 
Regular mail or courier 


For information transmitted 
internally, use locked blue bag, 
marked "Confidential" or "To 
be Opened by Addressee Only" 
via internal mail/courier 

For information transmitted 
externally, use sealed envelope 
or tamper evident packaging 
marked "Confidential" or "To 
be Opened by Addressee Only" 
via regular mail or courier as 
appropriate 


For information transmitted 
internally, use tamper evident 
packaging (e.g., locked blue bag 
with inside envelope signed over 
seal to reveal evidence of 
tampering), marked "Restricted" 
or "To be Opened by Addressee 
Only" via internal mail/courier 
For information transmitted 
externally, use tamper evident 
RA marked "Restricted" 
"To be Opened by Addressee 
Only" via registered mail or 
courier as appropriate 
Information transmitted 
internally or externally will be 
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When transmiittihe data and itor misto that is classified as Internal Use, Confidential or Restricted 


Message sent in such a way to 
prevent interception, 
modification, or unauthorized 
receipt en route or at 
destination (e.g., encryption 
used to send/authenticate 
message) 

CoA Email is encrypted by 
default as it is sent 


Information sent in such a way 
to prevent interception, 
modification, or unauthorized 
receipt en route or at 
destination (e.g., encryption 
used to send/authenticate 
message) 

When sent via email, subject line 
will contain "Confidential" as 
part of the subject line 

Audit trail of access 


Message sent in such a way to 
prevent interception, 
modification or unauthorized 


receipt en route or at 
destination (e.g., encryption 
used to send/authenticate 
message) 

When transmitting Restricted 
information externally, the file 
must be password protected 
Audit trail of access 
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Information Security Handling Process 


under a continuous chain of 
custody with documented 


receipts covering each individual 
who obtains custody 
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When handling information that is classified Internal Use, Confidential or Restricted, additional 
security measures should be taken commensurate with information value, sensitivity, and the risk 
level identified: 


e. Do not leave documents and screens unattended or unsecured. 
e Position documents and screens to prevent inadvertent disclosure. 
e Access information from its original source when at all possible. 


e Keep hard copies or printed versions of information to a minimum. 

e Transitory information (convenience copies, etc.) must be disposed of in a secure shredding 
receptacle. All other information, in any form or medium, must be retained and disposed of as 
required by the City of Airdrie Retention Schedule and Disposition Process. 


e Erase all white/smart boards at the end of meetings. 


e All information collections, in any form, containing differing classification levels must be 
classified as a whole at the highest classification level within the collection. (e.g., file, 


database, emails and attachments, filing cabinet). 


e_ |f there is any ambiguity with respect to confidentiality, the information will be classified as 
Confidential until it can be definitively classified at a lower level. 


e information Security Classification Standard 

e Administrative Policy - Computer Use 

e Effective Jan 1, 2019 -this process does not apply to information created or received prior 
to this date (e.g., labelling) 


Information Security Classification _ Internal Use 5 
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To set the authority and process for initiating, implementing, monitoring, and releasing legal holds on 
City information (physical and electronic) in the event of litigation, anticipated litigation, audit, 
investigation, Freedom of Information and Protection of Privacy (FOIP) request or other such matter to 
avoid evidence spoliation. 


This process applies to all information, regardless of form, made or received in the transaction of the 
City’s business as well as requests related to the Freedom of Information and Protection of Privacy Act 
(FOIP). Compliance is required by all City business units, employees, volunteers, consultants and 
contractors. 


Disposition — The disposal of information no longer needed for day-to-day operations by a City 
department/business unit through destruction, secure destruction, or transfer of records of enduring 
value to archives. 


Electronic information - All forms of electronic information, including documents or data stored in 
systems, including but not limited to, email, word processing documents, presentations, calendars, 
spreadsheets, voice messages, videos, photographs, text messages, or information stored in any mobile 
devices. | 


Freedom of Information and Protection of Privacy (FOIP) Request — A formal method of requesting 
information held by public bodies through the Freedom of Information and Protection of Privacy Act. 


Legal Hold — A process that an organization uses to prohibit destruction and to preserve all information, 
regardless of form, related to the nature or subject of the anticipated legal action, audit, investigation, 
FOIP reguest or other such matter to avoid evidence spoliation. 


Legal Hold Notice — A directive providing instructions to individuals and/or business units to ensure the 
preservation of all information in the City's possession or control related to the subject matter. 


Litigation - The process of taking a case to a court of law so that a judgment can be made. 


Preservation of information — Protection from destruction, alteration, or mutilation to prevent 
spoliation. 


Responsive or Relevant Information — Information related to the nature or subject of potential legal 
actions. 


Retention Schedule — The timetable that identifies the retention period during which information must 
be retained before disposition. 


Spoliation — The intentional, reckless, or negligent withholding, hiding, altering, fabricating, or 
destroying of evidence (information) relevant to a legal proceeding. 
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Transitory Information - Information in any format (paper or electronic) that is required for a limited 
time and does not need to be filed or retained. It is used to complete a routine action in the preparation 
of final records or as information or convenience copies by business units or individuals. 


The City of Airdrie has a duty to preserve relevant information whenever litigation or a FOIP request is 
reasonably anticipated, threatened or pending. This duty arises regardless of whether the organization is 
the initiator or the object of litigation. 


Once a legal hold is triggered there is a duty to preserve all information which may be deemed to be 
relevant to supporting the litigation. The duty to preserve supersedes Information Governance & 
Management policies or retention and disposal schedules that would otherwise result in the destruction 
of information. The organization must take the necessary steps to implement the hold and suspend the 
disposal of all information, including transitory, in all formats which may be deemed to be relevant. 


Legal holds will be initiated by Legislative Services: 


1. Ifa business unit receives notice of action or potential action; 

2. When a formal notice of legal action has been received (e.g., statement of claim, originating 
application, subpoena, other formal notice of the commencement of legal action); 

3. When the City has been notified of potential or anticipated legal action; 

4. When the City has received a reguest for information under the Freedom of Information and 
Protection of Privacy Act (FOIP) or has been notified of review, investigation or inguiries by the 
Office of the Information & Privacy Commissioner; 

5. In any other circumstances the City deems appropriate or legislation requires. 
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1. Determine if circumstances merit the need for a legal hold; 

2. Notify business units or individuals of accountability of the initiation of a Legal Hold and the 
information that is considered responsive or relevant; this will be in the form of a Legal Hold Notice; 
The following should be included in a Legal Hold Notice: 

a. an explanation of the preservation obligation and the consequences that can result from 

failing to follow the directive; 

b. an explanation that the Legal Hold Notice is privileged and instructions to not discuss the 
matter with individuals other than Team Leader/Manager/Director or Legislative Services; 
a description of the matter, including relevant time period; 

a description of the scope of information to be preserved; 

a description of the types of information to be preserved; 

a directive to cease document retention/destruction polices; 

directions to departing employees (if applicable); 

instructions on how to handle instant messaging, blogging and social media and personal 

devices; 
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i. instructions on who to contact with questions relating to the legal hold; 
j. a read receipt will be accepted as an acknowledgement that the employee has read, 
understands and agrees to be bound by the legal hold; 
3. Develop preservation plan(s) if necessary; “ 
4. Coordinate consistent preservation and production advice and practices; 
5. Assist business units or individuals to comply with the Legal Hold Notice; 
6. Review the legal hold periodically and modify if required; 
7. Ensure follow up or any other required actions; 
8. Retain a copy of the Legal Hold Notice that has been issued and a distribution list for the notice for 
the duration of hold; 
9. Maintain Legal Hold Register; 
10. Remove the hold when appropriate to do so (see Removal of Legal Hold). 
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1. Notify Legislative Services if notified of legal action or potential action; 

2. Review the Legal Hold Notice and acknowledge its receipt (a read receipt is accepted as an 
acknowledgement); 

3. Request that relevant staff identify the location of all potentially responsive or relevant information 
and provide a hard copy to Legislative Services with file path duly noted on the document (as an 
organization do we want this to become the standard?). If the information is currently being worked 
on, the documents are to be provided to Legislative Services as creation or revision occurs; 

4. Provide relevant computers/devices (including personally-owned computers and mobile devices if 
requested); 

5. Comply with any instructions accompanying the Legal Hold Notice; 

6. Contact Legislative Services when needing access to a document or file containing information that 
may be relevant to the legal hold; | 

7. Retain a copy of the Legal Hold Notice that has been issued for the duration of the legal hold; 

8. Resume normal business practice upon notification of removal of the legal hold. 


1. Review the Legal Hold Notice and acknowledge its receipt in writing (read receipt is not acceptable); 

2. Suspend any retention policy or records retention and disposal schedule affected by the legal hold; 

3. Identify any potential sources of relevant information in all formats; 

4. Collect and preserve information as determined in the Legal Hold Notice (see Preservation of 
Information); 

5. Comply with any instructions accompanying the Legal Hold Notice; 

6. Assist in departmental compliance; 

7. Retain an official copy of the Legal Hold Notice that has been issued and a distribution list for the 
Legal Hold Notice; | 

8. Resume records retention schedule, authorized disposal of records and resumption of transitory 
records disposal and normal business practice upon notification of removal of the legal hold; 

9. Collect/maintain the overall record of the legal hold from all relevant departments once the legal 
hold is removed. 
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1. Review the Legal Hold Notice and acknowledge its receipt (a read receipt is accepted as an 
acknowledgement); 

2. Work with Legislative Services, IGM, and the business unit to identify the scope of electronic records 
that must be preserved, the identification methods, collection processes, and searches; 

3. Collect and preserve electronic information if possible to do so without changing the nature of the 

information; | 

Make the electronic records available in appropriate formats; 

Comply with any instructions accompanying the Legal Hold Notice; 

6. Retain a copy of the Legal Hold Notice that has been issued and a distribution list for the Legal Hold 
Notice for the duration of the legal hold; 

7. Resume normal business practice upon notification of removal of the legal hold. 
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1. TheCity of Airdrie is required to preserve all information in its custody and control that is responsive 
or relevant to a Legal Hold Notice including the following: 

a. physical/paper (including information in inactive storage); 

b. electronic; 

c. transitory information; 

d. information that may reside on other devices owned or used by employees in the course of their 
employment. 

2. Responsive or relevant information must be maintained until the resolution of the legal issue or 
request: 

a. information must not be manually destroyed or modified once an employee is aware of a 
request to implement a legal hold. If the information is currently being worked on, the 
documents are to be provided to Legislative Services as creation or revision occurs; 

b. the disposition process must be halted for any relevant information that is scheduled for 
destruction, disposal or deletion (including transitory information); 

c. whenever possible, information will be maintained in its original format. 

3. Examples of preservation methods may include but not be limited to: 

a. for electronic information suspension of auto-delete program(s); securing or imaging a hard- 
drive; securing and preserving a backup tape or backup media; and/or sequestering information; 

b. for paper information making photocopies, sequestering original paper information to protect 
from loss, destruction or alteration; and/or storage in secured IGM location or other approved 
secure area; 

c. anyother instruction contained in the Legal Hold Notice as deemed advisable. 
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1. Insurance and Risk Management is obligated to notify LS when any issue subject to legal hold has 
been concluded; 
2. When the litigation has been concluded, or impending litigation, investigation or request has been 
resolved: 
a. Legislative Services will notify the appropriate individuals on the notification list that the legal 
hold has been removed; 
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b. released information will resume normal retention requirements; 
c. transitory information may be disposed of without further approval. 
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Failure to implement a legal hold could result in significant negative consequences to the City. It could 
result in the City being unable to prove its legal claim against others, a court may make an adverse 
inference against the City for failing to produce information, the City could be subject to the striking of 
some or all of its claims or defenses, or the City may have to pay costs or other penalties. 


Any violations of this process will be managed in accordance with City's Management of Performance 


program. 
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Information provides evidence of business decisions, plans and actions, and a background and basis for 
future actions. It demonstrates accountability and preserves the documentary history of the City. 
Disposition is an important part of managing information, ensures that the City retains information for 
as long as it is needed and then, when no longer needed, destroys it in an appropriate manner or 
permanently archives it due to its historical value. 


The purpose of this Process is to outline the reguirements to ensure that information is dispositioned 
safely, securely, and at the right time in accordance with the City of Airdrie Information Governance and 
Management Policy, Retention and Disposition Bylaw No. B-14/2018 and Retention Schedule. 


A managed disposal process reduces storage costs incurred by using office or server space to maintain 
information no longer needed. It supports compliance with legal requirements and provides consistency 
across the organization for the retention and disposition of information. 


This process applies to the disposition of all information in all formats that is created or received during 
the course of business at the City of Airdrie, including but not limited to: 


e handwritten, typed, or printed hardcopy (i.e., paper) documents; 


e electronic records and documents (e.g., information stored on networks, hard drives, CDs, USB 
drives, DVDs, tapes); 


e video or digital images (e.g., CCTV, in car camera); 

e graphic representations; 

e information contained in business or transactional systems; 

e information contained on network servers and/or document manasenient systems; and 
e recorded audio material (e.g., in car camera, voice recordings). 


Information that is transitory (of limited value) is excluded from this process and will be handled as 
outlined in the Transitory Information Guideline. All information appraised as having historical or other 
value to warrant continued preservation will be retained permanently. 


Physical information no longer required for daily business use (excluding transitory information) will be 
transferred to Information Governance and Management (IGM) and managed in secure file rooms; 
electronic information will be managed in the Electronic Document and Records Management System 
(EDRMS) or other approved business system. All information will be maintained in accordance with the 
City of Airdrie's Retention Schedule until it is eligible for disposition. 
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Before disposition can occur, the following must be confirmed: 


1. the information has been authorized for destruction in accordance with the requirements of the 
City’s approved Retention Schedule; 


2. there is no active or pending audit, FOIP request, investigation, or legal matter that involves the 
information in question (see Legal Hold Process); 


3. the information is no longer required under any other legislation and all legal requirements are 
fulfilled; and 


4. the records are of no further administrative or business use. 
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IGM will identify information that is eligible for disposition on an annual basis. IGM will complete a 
comprehensive inventory and review to confirm eligibility of the information to be dispositioned. 


An eligibility list will be provided to the Team Leader and Manager/Director of the originating business 
unit for review, approval and sign-off. 


Information holds may be requested by a Team Leader/Manager on information eligible for final 
disposition if there is an immediate or ongoing need for the information; e.g., the information is 
required for current or upcoming litigation, audits, inquiries or requests for information under the 
Freedom of Information and Protection of Privacy Act. A hold may also be placed by IGM if the 
retention of the scheduled information in question is under review or amendment. 


Once approved by the business unit, the eligible information will be given final review, approval and 
sign-off by IGM prior to disposition and will serve as documentation of the information destroyed. 
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Destruction of information must be irreversible to mitigate the risk of unauthorized access or of it being 
recovered, retrieved or reconstructed. Once eligible information has received final approval for 
disposition by IGM, it will be destroyed by the appropriate method: 


1. Physical Information: 


All paper information will be destroyed (cross-cut shredding) on-site by the approved shredding 
service and witnessed by IGM. 
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Disposition of Physical Source Documents: 


Original paper source documents can be disposed of after digitization (scanning) where the 
process has been approved and documented procedures exist, and all Quality Assurance 
procedures are completed as outlined in the Digitization Procedure Manual. 


2. Digital Information: 


All digital/electronic information will be deleted and/or overwritten by an authorized system 
administrator to ensure that the information is inaccessible and unrecoverable. This will include 
backup media such as magnetic tapes, CDs, storage area networks (SANs). 


3. Other Electronic Media: 


Computer hard drives will be overwritten with 3 passes of a data erasure software prior to 
being reused internally/externally or decommissioned. Hard drives can be shredded in the 
same way as paper or destroyed by demolition with certificate of secure destruction. 


Photocopiers and multifunction printers on lease must have the hard drives overwritten 
prior to being replaced. 
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The destruction of all records must be appropriately documented so that the City is able to provide 
proof of when information has been destroyed. Proof of destruction may be required in legal 
proceedings or in response to FOIP requests. Once the information has been destroyed, it is important 
that the City retains evidence that destruction has occurred. 


1. Physical Information: 


a. Alllists of approved eligible information received from business units will be retained 
permanently. Documentation will outline the information destroyed, including: 
. Record series description 
* Box Number 
e Date of destruction 
e Master Area 
e Date span of the records series 
e Retention code and description 
e Approval and authorized signature 

b. Acertificate of destruction provided by the destruction service vendor including the number 
of boxes destroyed and the date of destruction will also be required. 
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c. An affidavit confirming that the destruction took place, the date, time and method of 
destruction will be signed by the IGM witnesses of the destruction. 


d. All documentation will be retained together permanently. 
2. Digital Information: 


a. In all systems where information is maintained, execution of disposal schedules will provide 
details of the electronic information that has been deleted, including but not limited to: 


e Title 
e Date of destruction 
ə Metadata of the information (creator, file type, retention classification) 
e Approvals for destruction 
b. The disposition certificate will be preserved permanently. 
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This Process will be approved by the Information Governance and Management Steering Committee. It 
is to be formally reviewed at a minimum of every two years. 
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Employees should refer to the following for more information: 


City of Airdrie Information Governance and Management Policy 
City of Airdrie Retention and Disposition Bylaw No. B-14/2018 
City of Airdrie Retention Schedule 

City of Airdrie Retention Schedule Change Process 

City of Airdrie Legal Hold Process 
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PRIVACY BREACH MANAGEMENT 


A privacy breach occurs when there is unauthorized access to or collection, use, disclosure or 
disposal of personal information. Such activity is “unauthorized” if it occurs in contravention of 
the Freedom of Information and Protection of Privacy Act. 


A typical privacy breach would involve the personal information of our residents, clients or 
employees being stolen, lost or mistakenly disclosed (for instance if a computer containing 
personal information is stolen or personal information is mistakenly emailed to the wrong person). 


Some examples of what a privacy breach may look like are: 


e A person hacks into the City's computer system and obtains personal or confidential third 
party business information; 

e An employee sends a fax or email containing personal information to the wrong number 
or email address; 

e An employee mails a letter containing personal information to the wrong address; 

e An employee takes work home that contains privileged, personal or confidential third party 
business information and a spouse or any other person reads that information. 

e Files or paper records containing personal or confidential third party business information 
are lost or stolen. 

e Laptops that are able to provide access to personal or confidential third party business 
information are lost or stolen. 

e City cellphones are lost or stolen. 

e Flash drives containing personal or confidential third party business information are lost 
or stolen. 


What should you do in the event of any known or suspected breach of 
personal and/or confidential third party business information? 


IMMEDIATELY contact Legislative Services at 8816 or legislative.services@airdrie.ca. 
2. Contact your supervisor. 


Contain the breach: Immediately stop the unauthorized practice, recover the records 
and correct weaknesses in physical security 


While reporting a privacy breach to the Information and Privacy Commissioner is not mandatory 
under FOIP, any breach of privacy can have serious implications for both the person whose 
privacy was breached and the City, so it is critical that the City has a privacy breach management 
process in place to deal with any privacy breach. 


Attached is a document produced by the Office of the Information and Privacy Commissioner of 
Alberta that outlines various different causes of breach that may result from human error, theft, 
system compromise or inadequate access control and includes recommendations on how to 
prevent such breaches. | 
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BREACH MANAGEMENT PROCESS 
(for Legislative Services) 


Immediate response to any breach or suspected breach is required immediately in every instance. 
The first 3 steps indicated below should be undertaken concurrently or in quick succession. 


Step 1: CONTAIN THE BREACH - 


> The breach needs to be contained immediately, whether this means stopping the 
unauthorized practice, recovering the records, shutting down the system that was breached 
or correcting weaknesses in physical security. This may have already been done by the unit 
that discovered the breach, but please confirm the steps that were taken to ensure 
containment has been handled adequately. 


> If the breach involves theft or other criminal activity, notify the RCMP. 


step 2: RISK EVALUATION 


Conducting a risk assessment is vital to determine whether any other steps are required to be 
taken immediately. Factors to be taken into consideration include: 


» Personal Information Involved 


o What types of data were involved in the breach? The more sensitive the data, the 
higher the risk (SIN numbers and financial information are two examples) 


o Consider what the possible uses could be for the personal information that was 
breached? Could it be used for identity theft, fraud or other detrimental purposes? 


» Cause and Extent of the Breach 

o What is the cause of the breach? 

o Is there a risk of ongoing or further exposure of the information? 

o What was the extent of the unauthorized collection, use or disclosure, including the 
number of likely recipients and the risk of further access, use or disclosure, including 
in mass media or online? 

o Is the information encrypted or otherwise not readily accessible? 

o What steps have you already taken to minimize the harm? 

» Individuals Affected by the Breach 


o How many individuals are affected by the breach? 


o Who was affected by the breach: employees, public, contractors, clients, service 
providers, other organizations? 


» Foreseeable Harm from the Breach 
o Is there any relationship between the unauthorized recipients and the data subject? 
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Step 3: 


What harm to the individuals will result from the breach? Harm may include: 


= Security risk (physical safety, for example); 

= identity theft or fraud; 

" loss of business or employment opportunities; and 

= hurt, humiliation, damage to reputation or relationships. 


What harm could result to the organization, public body or custodian as a result of the 
breach? For example: 


=" loss of trust in the organization, public body, or custodian; 
= loss of assets; and 
= financial exposure. 


What harm could result to the public as a result of the breach? For example: 


= risk to public health; and 
= risk to public safety. 


NOTIFICATION 


As a public body that collects and holds personal information, we are responsible for notifying 
affected individuals in the event of a privacy breach. Any breach of information by a third party 
contracting with the City that has collected personal information on the City's behalf has a duty 
to notify the City. It is then the City’s responsibility to provide notification. 


The City must look at the risk assessment and weigh whether notification is necessary to avoid 
or mitigate harm to an individual whose personal information has been inappropriately collected, 
sued or disclosed in order to determine whether notification is required. 


If it is decided that notification is required, the following steps should be taken: 


> Notification to Affected Individuals 


some things to consider in determining whether notification is necessary: 


O 


O 


Does legislation reguire notification? 


Contractual obligations reguire notification: Does the City have a contractual 
obligation to notify affected individuals in the event of a privacy breach or loss of 
data? | 


Risk of identity theft or fraud: How reasonable is the risk? Identity theft is a 
concern if the breach includes unencrypted information such as names in 
combination with SINs, credit card numbers, driver's license numbers, personal 
health numbers, debit card numbers with password information or any other 
information that can be used for fraud by third parties. 


Risk of physical harm: Does the loss of information place any individual at risk of 
physical harm, stalking or harassment? 


Risk of hurt, humiliation or damage to reputation: This type of harm can occur 
with the loss of information such as disciplinary records. 
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Risk of loss of business or employment opportunities: Could the loss of 
information result in damage to the reputation of an individual, affecting business or 
employment opportunities? 


» When and How to Notify 


When: As soon as possible following a breach. If the RCMP have been contacted, please 
check with them to ensure notification will not impact a criminal investigation. 


How: Direct notification to affected individuals is preferred, either by telephone, letter or in 
person, especially where: 


e the identities of the individuals are known; 

e current contact information for the affected individuals is available: 

e individuals affected by the breach require detailed information in order to properly protect 
themselves from any potential harm resulting from the breach; and/or 

e individuals affected by the breach may have difficulty understanding an indirect 
notification (due to mental capacity, age, language, etc.). 


We should only use indirect notification methods (posting on our website, notices in the 
newspaper, on the radio or posted elsewhere) in the following cases: 


direct notification could cause further harm; 

the costs of direct notification would be prohibitive; 

we do not have sufficient contact information to support direct notification; or 

due to the large number of affected individuals, direct notification would be impractical. 


** In some cases multiple forms of notification may be appropriate and the most effective. 


» What Should the Notification Include? 


e 


o 


date of the breach; 

description of the breach (a general description of what occurred); 

description of the information inappropriately accessed, collected, used or disclosed; 
the steps taken so far to mitigate the harm; 

the next steps planned and any long term plans to prevent future breaches; 


the steps the individual can take to further mitigate the risk of harm. We should 
provide information about how individuals can protect themselves. This may include: 


= how to contact credit reporting agencies; or 

"^ information on how to change a driver's license number. 
contact information of an individual within the City who can answer guestions or 
provide further information. This should be discussed and confirmed by the FOIP 


Head. 


that individuals have a right to complain to the Office of the Information and Privacy 
Commissioner, including contact information for the Commissioner's office. 
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> Others to Contact 


Even if the City decides notification to affected individuals is not necessary, we still need to 
consider whether the following should be informed of the breach: 


O 


O 


RCMP if theft or another crime is suspected; 


Insurers or others if required by contractual obligations; 


Professional or other regulatory bodies if professional or regulatory standards 
require notification to these bodies; and 


Office of the Information and Privacy Commissioner. Consider the following in 
determining whether to report a breach to the OIPC: 


the sensitivity of the personal information; 

whether the disclosed information could be used to commit identity theft; 
whether there is a reasonable chance of harm from the disclosure including 
non-pecuniary losses; 

the number of people affected by the breach; and 

whether the information was fully recovered without further disclosure. 


step 4: PREVENTION 


Once the immediate steps are taken to mitigate the risks associated with the breach, the cause 
of the breach must be thoroughly investigated (this may involve an audit of both physical and 
technical security). The Senior Leadership Team should be briefed on all events related to the 
breach and next steps determined. The following items should be presented to SLT for 
consideration: 


O 


O 


evaluation of current safeguards and development or improvement of the same; 


review of internal policies on personal information and update any policies as 
necessary with lessons learned from investigation and breach response; 


audit of breach process/plan; and 


look at employee training program and amend as necessary. 
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Acquiring a New Business System 


RFI - Exception 
If an RFI (request for information) is needed, that would process would 
occur before this process and would be handled on a case by case- 


basis. Please reach out to the IT Manager and your Strategic BA, once 
approved by your area Director to move forward, if you believe that an 
RFI is required for your business system request. 


Resources from IT, SBS, and 
Business Unit must be assigned 


CC“ ee ' 7 © 


Intemal Use 
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here before moving forward 
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BSA Stage 1 willbe completed by 
IGM & whichever group (IT or 
SBS) is doing the business case 


reguirements 


Reguirements would include 
PlA requirements and those 
identified in the BSA in addition 
to the Business Unit functional 


IGM, LS, & IT Technical 


personnel would evaluate the 


PIA & BSA reguirements as 
appropriate to each area; 
Business Unit evaluates the 
functional reguirements 


29 
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Revision # 2 


_ Use to create different versions of the process until ready-to-use - 


Date: August, 2018 


Approved by: ] 


System Name: Name here A CITY Of 


Assessor Name: Name here I RD R I E 
à COMMUNITY & CR mes) OPPORTUNETY 


Assessment Date: Date here 


is Assessment - Risk Assessment 
The Risk Assessment is the first stage of the Business Systems Assessment used by the City of Airdrie to evaluate what 
information will be created, managed and stored in the business system and the associated risk and value of that 
information. The Risk Assessment is then used to determine next steps regarding the management of the information. 


Phase 1: Risk assessment checklist _ 


ERU 


1 What is the purpose or Describe what the system will do or 
objective of the system? | business process it will address. 


What information is Include whether documents will be 
stored in the system? stored in the system or database. 


Security Classification information such as personnel 
Standard? information, in camera minutes, 
contracts/agreements etc. 


Business information of a third party 
including trade secrets, technical 
information, scientific or financial 
information. 


If Yes for any of the information 
types listed, an impact assessment 

must be completed (see 1.6 of PIA). 
Contact Legislative Services. 


Is the information Personal information includes any 
personal as defined in identifiable information about an 
the FOIP Act or individual (name, account number, 
confidential or restricted | image). 

as defined in the City of 

Airdrie's Information Confidential information includes 


If No go to Q4 below 


2 
3 
4 Does or will the system Is the information contained in this 
hold unique system duplicated in another 
information? system? 
A decision has to be made to 


determine if the information 
contained in this system is unique 


Stage 1: Business Systems Assessment — Risk Assessment Internal Use 1 
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System Name: Name here I CITY RI E 
Assessor Name: Name here AIRDRIE 
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Based on the answers in Stage 1, this additional assessment is required against one (or more) of four additional 
modules. As in Stage 1, respond to all questions in the appropriate module by providing a 'Yes' or 'No' response. 


A 'Yes' response means functionality exists. No further action is required. Add a review date and document the 
assessment outcomes and other relevant information in Stage 3: System Information Governance and Management 
Plan. 


A 'No' response to each guestion will mean that this specific functionality is not met. Where a gap (a No response) 
exists it is necessary to identify how the functionality will be achieved. If it is believed the gap is acceptable or 
necessary (e.g., a cost effective mitigation is not available), approval to acguire or use the system is reguired from 
the Information Governance and Management Steering Committee,and if required, the Senior Leadership Team. All 
options and decisions should be captured in Stage 3, the System Information Governance and Management Plan. 


Module 1: Information is Trusted 
Considerations For 'No' responses, | Date 
how will this Assessed 
functionality be 
achieved? 
1. Canthe information | Ability to demonstrate: 
be proven to be who created it 
authentic? when it was created 

who modified it 

when it was modified — - 

electronic signatures (if to be 

used) are unique, identify the 

individual using the process and 

can be linked with an electronic 

document to determine if 

modified after the document 

was signed 

electronic documents requiring 

long term (20 + years) are in 

PFD/A format to prevent 

obsolescence 


2. Doesthe system All business systems procured by the 
meet the remainder | City of Airdrie after October 31, 
of the minimum 2017, will meet minimum metadata 
metadata standard? | standards. 


3. Canunauthorized Do the following exist: 
changes to the e human-readable audit logs 
information be showing changes to content 
identified or all relevant actions captured in 
prevented? an audit trail 
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System Name: Name here 
Assessor Name: Name here 
Assessment Date: Date here 


Module 2: Disposal is Accountable 


Stage 


2: Business Systems Assessment — IGM Functionality 


Where the system 
contains 
information that has 
a retention period 
(disposal 
classification) less 
than permanent, 
can the system 
manage the disposal 
of information 
based on the 
applicable retention 
period? 

Is the system able to 
prevent information 
modification or 
destruction in the 
event of a disposal 
freeze/hold? 


Does the system 
have appropriate 
information to 
demonstrate 
accountability 
needs? 


Can destruction be 
conducted securely 
and in line with 
destruction process 
and any other 
relevant 
policies/standards 
for destruction? 


Processed under the provisions of the Access to 


Considerations 


Can the system accommodate 
destroying information based on the 
applicable retention period (e.g. 
invoices vs contracts)? 


What are the risks if legal hold can’t 
be applied? 


Following destruction of information, 
the system should maintain a record 
of what has been destroyed in case it 
is needed to defend the destruction 
if challenged. 


Consider the risks if: 

e donot know what has been 
destroyed 
cannot prove whether or not 
specific information existed at a 
particular date 
cannot show under what 
authority and with what 
approval the information was 
destroyed 

See Disposition of Information 

Process for secure disposal of 

electronic information 


Internal Use 
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For 'No' responses, | Date 
how will this 


Reviewed 
functionality be 
achieved? 


System Name: Name here A CITY of 
Assessor Name: Name here I LDR I E 
Assessment Date: Date here COMMENIYY & Le OPPORTUNITY 


Module 3: Export/import 


Can the system 
accommodate for 
the export of all 
information in a 
usable format? 


If applicable, does 
the system 
accommodate for 
the import of 
records into the 
system? 


Module 4: Reporting 


Can or will the 
system generate 
reports relevant to 
Information 
Governance and 
Management 
processes? 


Can or will the 
system create 
automatic alerts in 


response to specific 


triggers? 


Processed under the provisions of the Access to 


Considerations For 'No' responses, | Date 
how will this Reviewed 
functionality be 
achieved? 
Consider the risks if: 
e the export, import or migration 

does not include all metadata 

required 

you are unable to access or use 

the exported, imported or 

migrated information 

You are unable to determine if 

all records were 

complete/unaltered in the 

course of transmission or 

storage 


Consider the risks if: 

e the system will need to support 
import if it is likely to replace an 
existing system and will be 
required to import records from 
it 
the system is limited in the 
format or types of information 
that can be imported 
metadata that is required 
cannot be imported as reguired 


Considerations 
responses, how Reviewed 
will this 
functionality be 
achieved? 
Accurate and efficient reporting is 
essential to accountable information 
governance and management. 


Reports typically reguired would 
include: 
e #of records due for destruction 
on a specific date 
# of records scheduled for 
disposition on a specific date or 
under a specific disposal class 
Alerts when specific information is 
due for destruction would be helpful: 
e if you are implementing 
automated disposal 


Stage 2: Business Systems Assessment — IGM Functionality Internal Use 3 
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System Name: Name here A CITY of 
Assessor Name: Name here I R I E 


COMMUNITY & VE OPPORTUNITY 


Assessment Date: Date here 


Stage 2: Business Systems Assessment — IGM Functionality Internal Use 4 
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System Name: Name here A CITY of 
Assessor Name: Name here I LDR I E 
COMMUNITY & Cr zi Re OPPORTUNITY 
Assessment Date: Date here 
If Yes go to Q6 below 


|. If No Ber to Q5 below D 


(Y/N) 


| J L 


be the authoritative information to be shared within your 
source of truth or relied | department or the organization that 
No. | Question Explanation Response Response Details 
a 
CN Is the risk or value of the | The organization may have to 


on to create an is deemed reliable and trustworthy. 
Stage 1: Business Systems Assessment — Risk Assessment Internal Use 2 


and the only version which cannot be 
sourced elsewhere. 


Examples where the information is 
not unique: 


e information is created and 
stored on a network drive or 
in the SharePoint and saved 
in this system or linked to 
this system 

e any system where 
information is routinely 
exported and managed in 
another system, for 
example Outlook emails 
that are saved to 
SharePoint. 


authoritative record? 


Authenticity and integrity of a 
document and the process for 
signing it electronically can be 
proven and used to determine any 
modifications after the electronic 
signature was incorporated in, 
attached to, or associated with the 
electronic document 


If not, does the system 
feed into a system that is 
an authoritative source 
of information? 


An example of a system that 
manages the authoritative source of 
truth: 


e Avanti (Employee Record) 
e GIS (Addressing ) 


If Yes go to Q6 


If No, document findings in Stage 3: 
System Information and Governance 
Management Plan. 
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CITY of 
Assessor Name: Name here I RDR I E 
V COMMUNITY & “mw OPPORTUNITY 
Assessment Date: Date here E 


information high enough | demonstrate that the 

to warrant additional information/record is authentic, 
controls to ensure that it | reliable and have integrity if the 

is trustworthy? subject of 


e  FOIP requests 

e Audits 
Investigations 
Legal proceedings 


Note: A yes response should also be 
recorded for any system that 
manages information identified as 
'Retain as Archives' (RA) in the 
Retention Schedule and any systems 
that do not yet have a set retention 
period in the City's Retention 
Schedule. 


If Yes, complete Stage 2: Module 1: 
Information is trusted 


Move on to Q7 


If No go to Q8 
e ee 
| (Y/N) | 


7 Is there a requirement to | |s there a requirement per the City’s 
destroy information in retention schedule to g destroy 
the system before the information earlier than the expected 
system would be life of the system? 


decommissioned? . 
What information retention applies 


to the information in the system? ( 


If the information contained in the 
system needs to be disposed of 
before the system is expected to be 
decommissioned, it must be either 
exported from the system or 
accountably destroyed within the 
system. A Yes should be recorded in 
this case. 


Note: A yes response should also be 
recorded for any systems that 
manage information identified as 
'Retain as Archives' (RA) in the 
Retention Schedule and any systems 
that do not yet have disposal 
coverage in the City's Retention 
Schedule. 


If Yes, complete Stage 2: Module 2: 


Stage 1: Business Systems Assessment — Risk Assessment Internal Use 3 
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Assessor Name: Name here 
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Disposal is accountable 
If No go to Q8 
— c | 
(Y/N) 


Does the information Will the information in the system 


need to be kept or need to be retained longer than the 
accessed beyond the system will be retained? 
expected life of the 


system? 


COMMUNITY & 


— 2 OPPORTUNITY 


Two options will exist: 


(a) Migrate all information to a 
new system 

(b) Migratesome information 
to the new system and 
retain the remaining 
information in the old 
system until it has met it's 
retention reguirements. 


Consider: 


e how long the organization will 
maintain the old system after it is 
replaced 

e whether the information 
remaining in the old system 
would be regular use 

e probable costs for maintaining 
the system after its active 

business use ends (for access 

purposes). Software and 
hardware requirements to 
produce information that is 
retained in the old system. 


Note: A yes response should also be 
recorded for any systems that 
manage information identified as 
Retain as Archives’ (RA) in the 
Retention Schedule and any systems 
that do not yet have disposal 
coverage in the City’s Retention 
Schedule. 


If Yes, you will need to assess 
functionality in Stage 2: Module 3: 
Export/import and Module 4: 

Reporting 


Document findings in the Stage 3: 
System Information and Governance 
Management Plan 
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A CITY Of 
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Assessment Date: Date here 


If No, document the outcome in 


Stage 3: System Information and 
Governance Management Plan 
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System name (Full product name) 
System common name/abbreviation 
Business owner (Business Unit/Department) 


Business process(es) supported by system What is this business system's purpose? E.g., 
supports Accounts Payable and Receivable; Facility 
bookings, Arena membership, etc. 


External or internal use only? Or both? 


. Access controls . Can user roles be defined? What are they? 
Application Server Version e.g. Avanti 10.2.1.80 
Operating System and Version e.g. Windows Server 2012 
Database Server(s) e.g. CDB01 — 10.2.1.70 
Referring Server e.g. MyNet/INET06 10.2.1.150 


Age of system/date acquired 
Upgrade due date 


Server location (physical) If cloud — note physical server and all backup server 
locations 


Current size of data holdings/Year over year growth 2017 
2018 


————— YNG Sn in - a s ene RHUN — a — EN ———— 


Ba 


System administrators Application SME 
Server SME 
Database SME 


Number of ai ao 

Is there a maintenance agreement with vendor? 
| Where is the source code kept? 

Wher is system documentation kept? 


Where is the configuration/customization 
documentation kept? 


Network Map 
Cost of system (initial procurement) 


Is there a related legacy system that has not been 
completely decommissioned? 


If yes, is the system read only? Who still has access 


System Information Governance and Management Plan internal Use 1 
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System Information Governance and Management Plan 


to it? 


Identify systems that use data from this system (and 
indicate what data is used) 


Identify systems that this system uses data from 


(and indicate what data is used) 


Is information from this system the authoritative 
source of the information? 


Retention specified? 


Are there privacy considerations for this 
Information? 


Is any information in the system subject to archival 
requirements (historical preservation purposes)? 


What information security classification(s) should be 
applied to the information or sets of information? 


Public/Internal/Confidential/Restricted 
What information security handling processes are to 
be applied to the information based on the 
information security classification applied? Refer to 
the Information Security Handling Process. 

Access Methods: 


System Information Governance and Management Plan 
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Describe 


What retention applies to the information managed 
in this system (using the records retention 
schedule)? List all codes that apply and to what 
information 

Yes/No 

Include link to PIA 


include link to PIB 


Yes/No 


| What information? 


If more than one applies, describe 


Indicate below all methods that apply (delete ones 
that will not be used and elaborate where 
additional handling processes will be used other 
than what is listed below). 


Public: 


e Access is open to the public and all 
employees, contractors, sub-contractors 
and agents 

e Can be published if it is of value/interest to 
the public by authorized publisher 


Internal Use: 


e Access to authorized employees, 
contractors, agents for business related 
purposes 

e Periodic audits to show protection is 
occurring will occur 


. Confidential, 


e Access limited to individuals in specific 
position, function, group or role 

e Log of access/actions will occur (specify 
what will be captured) 

e Periodic audits of adequate protection will 
occur (specify frequency and who will be 


Internal Use . 2 
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Storage Methods: 


System Information Governance and Management Plan 
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conducting audits) 
Restricted: 


e Access limited to named individuals or 
specific position 

e All access or actions are logged and subject 
to validation processes as appropriate 
(describe processes to be used) 


Public: 
e No labels will be used 
Internal Use: 


e Security classification will be captured in 
electronic document metadata 

e Security classification will be visible in 
footer of all pages of electronic documents 


Confidential: 


e Identify security classification in 
document metadata according to 
Minimum Metadata Standard 

e Information Security Classification will 
be visible in footer of all pages of 
electronic documents 

e The subject line of emails will contain 
"Confidential" as part of the subject line 


Restricted: 


e identify security classification in 
document metadata 

e Information security classification will be 
visible in footer of all pages of electronic 
documents 

e Subject line of emails will contain 
"Restricted" as part of the subject line 


Public: 


e No special storage requirements 


Internal Use: 


e All media under physical and/or logical 
access control e.g. limited system 
administration access, monitored 
connections to networks, system files and 
data) — provide details 


Confidential: 


e All media under physical and/or logical 
access control of confidential zone (e.g. 
authorized access and authenticated 
access — provide details 


Internal Use 3 
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Restricted: 

e All media under physical and/or 
logical access control of restricted 
zone (e.g. single or double 
authentication, encrypted data, 
audit and monitoring) — provide 
details 


Transmission Methods: . Public: 


e No special procedures are to be used 


Internal Use: 


e Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used). 


: Confidential: 


e Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used) 

e When sent via email subjection line 
contains “Confidential” as part of subject 
line 

e Audit trail of all access — describe 


Restricted: 


e Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used) 

e When transmitting Restricted information 
externally the file must be password 

. protected 

e Audit trail of access (includes who viewed 
the information ìn additìon to who created, 
or modified and when). 


Author name (ASA or business unit contact if 
completing the assessment or BSART) 


Business area contact name 
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Assessment outcomes 


e Provide details on outcomes of Stage 1: e.g. Stage 1 completed (date) — Information of 
Risk assessment sufficient risk to warrant completion of Stage 2 BSA 


e Provide details of risks/gaps identified in e.g. Stage 2 completed (date) — no gaps or issues 


Stage 2: Assessment of information exist or Gaps or Issues exits with mitigations 
management functionality identified 


e Provide where appropriate also details of 
Stage 3: Implementing solutions 


Date completed by assessor 


Date Reviewed by BSART 


IGMSC Approval: Le Y 
Ll N 
Date: 
Senior Leadership Approval, if reguired: IT. Y 
[] N 
Date: 
System Information Governance and Management Plan Internal Use 5 
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System name (Full product name) 
System common name/abbreviation 


Business owner (Business Unit/Department) 


Business process(es) supported by system What is this business system's purpose? E.g., 
supports Accounts Payable and Receivable; Facility 
bookings, Arena membership, etc. 


- External or internal use only? Or both? 


. Access controls Can user roles be defined? What are they? 
Application Server Version | e.g. Avanti 10.2.1.80 
Operating System and Version e.g. Windows Server 2012 
Database Server(s) e.g. CDBO1 - 10.2.1.70 
Referring Server e.g. MyNet/INETO6 10.2.1.150 


Age of system/date acquired 
Upgrade due date 


Server location (physical) If cloud — note physical server and all backup server 
_ locations 


Current size of data holdings/Year over year growth 2017 
2018 


System administrators Application SME 
— Server SME 
. Database SME 


Nines of IAN 

Isthere a CD — with vendor? 
Where is the cr code kept? 

where is system documentation kept? 


Where is the configuration/customization 
documentation kept? 


Network Map 
Cost of system (initial procurement) 


Is there a related legacy system that has not been 
completely decommissioned? 


If yes, is the system read only? Who still has access 
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System Information Governance and Management Plan 


to it? 
Identify systems that use data from this system (and 


indicate what data is used) 


Identify systems that this system uses data from 
. (and indicate what data is used) 


- - 


SOSA p DM Qu SENTERO AH EISSN NEI OMENS $ N Š 
Is information from this system the authoritative 
source of the information? 


. Retention specified? 


Are there privacy considerations for this 
Information? 


Is any information in the system subject to archival 
requirements (historical preservation purposes)? 


What information security classification(s) should be 
applied to the information or sets of information? 


Public/Internal/Confidential/Restricted 
What information security handling processes are to 
be applied to the information based on the 
information security classification applied? Refer to 
the Information Security Handling Process. 

Access Methods: 


System Information Governance and Management Plan 
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Yes/No 


Describe 


What retention applies to the information managed 
in this system (using the records retention 
schedule)? List all codes that apply and to what 
information 


Yes/No 
Include link to PIA 
Include link to PIB 


Yes/No 


What information? 


If more than one applies, describe 


Indicate below all methods that apply (delete ones 
that will not be used and elaborate where 
additional handling processes will be used other 
than what is listed below). 


Public: 


e Access is open to the public and all 
employees, contractors, sub-contractors 
and agents 

e Can be published if it is of value/interest to 
the public by authorized publisher 


Internal Use: 


e Access to authorized employees, 
contractors, agents for business related 
purposes 

e Periodic audits to show protection is 
occurring will occur 


Confidential, 


e Access limited to individuals in specific 
position, function, group or role 

e Log of access/actions will occur (specify 
what will be captured) 

e Periodic audits of adequate protection will 
occur (specify frequency and who will be 


Internal Use 2 
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Labelling Methods: 


Storage Methods: 
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conducting audits) 
Restricted: 


e Access limited to named individuals or 
specific position 

e All access or actions are logged and subject 
to validation processes as appropriate 
(describe processes to be used) 


Public: 
e No labels will be used 
Internal Use: 


e Security classification will be captured in 
electronic document metadata 
e Security classification will be visible in 
footer of all pages of electronic documents 


Confidential: 


e Identify security classification in 
document metadata according to 
Minimum Metadata Standard 

e Information Security Classification will 
be visible in footer of all pages of 
electronic documents 

e The subject line of emails will contain 
"Confidential" as part of the subject line 


Restricted: 


e Identify security classification in 
document metadata 

e Information security classification will be 
visible in footer of all pages of electronic 
documents 

e Subject line of emails will contain 
"Restricted" as part of the subject line 


Public: 


e No special storage requirements 


Internal Use: 


e All media under physical and/or logical 
access control e.g. limited system 
administration access, monitored 
connections to networks, system files and 
data) — provide details 


Confidential: 


e All media under physical and/or logical 

|. access control of confidentia! zone (e.g. 
authorized access and authenticated 
access — provide details 
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Transmission Methods: 


Author name (ASA or business unit contact if 


completing the assessment or BSART) 


Business area contact name 
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Restricted: 


Public: 


All media under physical and/or 
logical access control of restricted 
zone (e.g. single or double 
authentication, encrypted data, 
audit and monitoring) — provide 
details 


No special procedures are to be used 


Internal Use: 


Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used). 


Confidential: 


Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used) 

When sent via email subjection line 
contains "Confidential" as part of subject 
line 

Audit trail of all access — describe 


Restricted: 


Information sent in such a way to prevent 
interception, modification, or unauthorized 
receipt en route or at destination (e.g. 
encryption used) 

When transmitting Restricted information 
externally the file must be password 
protected 

Audit trail of access (includes who viewed 
the information in addition to who created, | 
or modified and when). 


Internal Use | 4 
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Assessment outcomes 


e Provide details on outcomes of Stage 1: e.g. Stage 1 completed (date) — Information of 
Risk assessment sufficient risk to warrant completion of Stage 2 BSA 


e Provide details of risks/gaps identified in e.g. Stage 2 completed (date) — no gaps or issues 


Stage 2: Assessment of information exist or Gaps or Issues exits with mitigations 
management functionality identified 


e Provide where appropriate also details of 
Stage 3: Implementing solutions 


Date completed by assessor 


Date Reviewed by BSART 


IGMSC Approval: Ll Y 
O N 
Date: 
Senior Leadership Approval, if required: Li Y 
LJ N 
Date: 
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BYLAW NO. B-11/2017 


OFFICE CONSOLIDATION 


Consolidated November 6, 2018 


Sharon Pollyck, City Clerk 


Of a Bylaw Totalling 
Five (5) pages. 
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BYLAW NO. B-11/2017 
OF THE CITY OF AIRDRIE 
IN THE PROVINCE OF ALBERTA 


Being a Corporate Records and Information Management retention and disposition bylaw. 


WHEREAS under the authority of and subject to the provisions of the Municipal 
Government Act, Revised Statutes of Alberta, 2000, Chapter M-26 and amendments thereto 
(hereinafter referred to as the “MGA"), Council may pass a bylaw respecting the retention and 
destruction of records and documents of the municipality; and 


WHEREAS under the authority of and subject to the provisions of the Freedom of 
Information and Protection of Privacy Act, Revised Statutes of Alberta, 2000, Chapter F-25, and 
amendments thereto (hereinafter referred to as “FOIP”), the municipality is to allow any person a 
right of access to the records in the custody and control of the municipality and is to control the 
manner in which the municipality may collect, use and disclose personal information from 
individuals, and 


WHEREAS under the authority of and subject to the provisions of the Electronic 
Transactions Act, Revised Statutes of Alberta, 2000, Chapter E-5.5, and amendments thereto, the 
municipality has the authority to create, record, transmit, or store information in digital form or any 
other intangible form by electronic, magnetic, or optical means, or any other means that have 
similar capabilities for creation, recording, transmission or storage 


WHEREAS Council has enacted Bylaw No. 32/99, establishing a retention and disposition 
bylaw; and | 


WHEREAS Council deems it advisable to repeal and replace Bylaw No. 32/99; 


NOW THEREFORE the Municipal Council of the City of Airdrie in Council duly assembled 
enacts as follows: 


1. SHORT TITLE 
' This Bylaw is called the "Records Retention and Disposition Bylaw." 
2. DEFINITIONS 
a. “City” means the corporation of the City of Airdrie. 
D. “City Department” means a department of the City. 
c. “City Manager” means the Chief Administrative Officer or his designate. 
d. “Confidential” means any record that contains personal information about individuals; 
third-party, commercial, financial, scientific or technical information supplied either 
explicitly or implicitly in confidence; or any other information protected under the 


FOIP. 


e. "Corporate Records” means all records of every City department, board, commission 
and committee. 
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“Disposition” means the disposal of records via destruction or transfer of records of 
enduring value to archives. 


“Record” means information in any recorded form that is in the custody and control of 


' the City, which includes but is not limited to documents, hand written notes, draft 


documents, voice mail, vouchers, drawings, letters, papers, e-mail, books, maps, 
photographs, calendars and post-it notes. 


“Retention Period” means the total length of time a record must be kept before final 
disposition is implemented. 


“Retention Schedule” means the timetable that identifies the retention period during 
which a record must be retained before disposition. 


“Transitory Record” means records in any media that have only temporary usefulness, 
are not part of an administrative or operational record series, are not regularly filed in a 
records information system, and are reguired only for a limited period of time for the 
completion of a routine action or the preparation of records, which include but are not 
limited to temporary information, duplicate documents, draft documents, publications, 
advertising material and blank information media. 


3. GENERAL 


It shall be the responsibility of the City Manager to provide for the adeguate storage and 
security of all City of Airdrie records. 


4. DISPOSITION OR DESTRUCTION OF RECORDS 


a. 


All transitory records, which do not contain confidential information, shall be disposed 
of at any time by City employees when they no longer serve any valid purpose. 


All transitory records containing potentially confidential information shall be disposed of 
in a secure manner at any time when they no longer serve any valid purpose. 


All records, excluding transitory records of the City, shall be destroyed in accordance 
with the retention schedule (Deleted). 
Bylaw No. B-14/2018 


The City Manager may authorize the destruction of the original copies of records prior 
to the time outlined in the retention schedule if those originals have been converted to 
electronic format that will enable copies of the originals to be made. 


Upon the City Manager being satisfied that the relevant retention period established by 
this Bylaw has expired and that no reason exists for further retention of a given class 
of records or specific records, the City Manager may then order the records to be 
disposed of. 


When records have been disposed of under this Bylaw, with the exception of transitory 
records, the City Manager shall certify same in writing. Such certification shall refer to 
the retention schedule and shall identify the records disposed of. 


The City Manager shall keep an index of all records that have been disposed of. 
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h. Where records are disposed of under this Bylaw, the proper and complete disposition 
thereof is the responsibility of the City Manager. 


i. Disposition of all records, except transitory records, shall be carried out in the 
presence of a witness. The person disposing of the records shall provide a Certificate 
of Destruction attesting to the time and location of the disposition of the records 
together with a list of the records disposed of and also the names of the persons who 
witnessed the disposition. The statement of disposition shall be permanently filed. 

j Election material that has been locked in ballot boxes may be destroyed in accordance 
with the provisions of the Local Authorities Election Act, Revised Statutes of Alberta, 
2000, Chapter L-21 and amendments thereto. 


5. DISCRETION 


The City Manager shall have the discretion to retain records longer than the period 
provided for in the retention schedule when the City Manager has: 


a. received an indication that there is or may be any litigation involving any said records; 
b. approved a Department request to keep any said records for a business purpose; or 
c. Approved a Department request to keep any said records for historical purposes. 


Such decisions to retain records longer than the period provided for herein shall be 
recorded in the records management system as an information hold. 


6. RETENTION AUDIT 


The City Manager shall ensure that the retention schedule is adhered to and that annual 
audits of the records be conducted to ensure compliance with this Bylaw. 


[Deleted] 
Bylaw No. B-14/2018 


7. REPEAL 


Bylaw No. 32/99, including any and all amendments, is hereby repealed in its entirety. 


READ a first time this 18" day of April, 2017. 
READ a second time this 18" day of April, 2017. 
READ a third time this 18" day of April, 2017. 


EXECUTED this 19" day of April, 2017. 


"P. Brown’ 
MAYOR 


"S. Pollyck" 
CITY CLERK 
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[Deleted] 


[Deleted] Bylaw No. B-14/2018 
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Legal Authority Text hon 
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[115] 
32945 MATTERS RELATING TO ASSESSMENT COMPLAINTS REGULATION, 2018 Canada Alberta zemplaints/ clerks/ board members/ training 0 o 
Alberta Regulation 201/2017 53 m 
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Retention Schedule Change Process COMMUNITY & (RES) OPPORTUNITY 


The City of Airdrie Retention Schedule is a living document. Changes in legislation, business need, or 
historical significance may necessitate changes to the Retention Schedule. The following outlines the 
process to be followed to make changes to the Retention Schedule. 


g 


mmu EoC AALS DECDRSNICIBIIPPIPO 
DOM LS AMNIS LR CONS IRIS TIR Re 
PROCESS AND RESPONSIBILITIES: 


ep 


vi EGO $ fe E] 2 y 
om Eee cee FM rey sey 2 an rox 
E Eper RADAS r a 


e The Retention Schedule will undergo a complete review of citations every 4 years. This may include 
the use of external contracted services, including outside legal review. 

e The Information Governance and Management (IGM) Team will be responsible for keeping scope 
notes (descriptions of what is included in a particular records series) up to date. | 

e Retention periods will not be specified in any City policies, standards, process, procedures or 
guidelines. They may refer to the Retention Schedule as the authoritative source for retention 
periods. 


Efsrsapipytme dm À heya M IBI t ë 
OUSTIESS Wh AGCUESTS 


If a business unit becomes aware of a change in business that would necessitate a change to the 
Retention Schedule within the four-year review cycle, a formal request will be made to make the 


appropriate changes. Requests to add new series or make retention periods longer will be considered 
through the following process: 


e Business unit will submit a request for change to the IGM team. Requests for changes are to be 
submitted by the Team Leader by email and will include: 


o Name of business unit making the request 

The name of the records series to be changed or added 

o Justification for the change or addition 
e = If legislative, citation to be provided if known (e.g., Act or Legislation) 
e If business need, written explanation to be provided 
è |f historical significance, written explanation to be provided 

o Business Unit Team Leader and Manager/Director approval 

o IGM Team Leader approval 


O 


e The IGM team will review the request to determine if further consultation with the business unit is 
reguired. Some retention periods affect multiple business units. Consultation will include all 
affected stakeholders and will aim to come to a consensus on the reguired retention period, 
although the final decision remains with the IGM Team Leader. 


e lf the change is approved by the IGM Team Leader, the Retention Schedule will be updated. IGM 
will communicate the approved change back to affected business units. 


Information Security Classification Internal Use 1 
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COMMUNITY 8 (fen OPPORTUNITY | 


Retention Schedule Change Process 


e This process shall not supersede any applicable legislation, bylaws and regulations, including 
Bylaw No. B-14/2018 and the Information Governance and Management Policy. 


Information Security Classification Internal Use 
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User formet] Rernove ME 


Note: Please ts sure to fill out ALL fields. If you require assistance you can call the SERVICE DESK st ext. 88617 


| &x REMOVE USER INFORMATION 


DEPARTMENT INFORMATION (TO BE REMOVED FROM) 


Department |Selectcepartment Y 


i k NETWORK INFORMATION 


B SECURITY INFORMATION (TO BE REMOVED) 


EA Remove all 


| & PHONE INFORMATION 
| Other phone equipment to be returned: 


Llecard O Smartphone 


General information [other cammentsk 


NENNEN 


Note: Please confirm that you have filled out ALL of the fields correctly then click "Send Remove User Request". 
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Database Access Request Form 
All database access must be approved by the City Clerks Office. 


Please contact the IT department first, to ensure the database owner is informed of the 
permissions being given. This applies to databases which are NOT owned by the 
department requesting the access. 


Complete this form and have it authorized by the City Clerks office and give a copy of 
the signed document to the IT department to have access rights set up. 


Rew —— 


po | First Name 


[| | Full Access [_| Read Only Access | | Partial Access 


IEEE 


I , hereby authorize to have access 
to the aforementioned database. 


Lou Dated: 
Team Leader Authorized Signature dd/mm/yyyy 


uL Dated 
City Clerks Authorized Signature dd/mm/yyyy 
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Access Request/Change Form 
“FMW Web” 


= USER I NFORMA' IO N oe : o a i "o 
Last Name 


ACCESS INFORMATION 


| | New User / Change 
| |  |BDateRequested pc 
Department —. |  .— 9 |Effective Date pM 
Ll ee 


Position / Role End Date (if applicable) | = | 


Operating Plan Module. 


Please provide the Cost Centers and select the level of Permission for which access is being granted 


Or 0 | 
—<——<— a 
ee a eee 


Capital Plan Module O | © 
O y OO Yes | No . 
Reporting Module 


= 


| es | No - 


© 


AM 


Please describe any acc 


The undersigned authorize the aforementioned User to 
form. 


NAME SIGNATURE | DATE 


System Administrator: 
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Access Request/Change Form 


“Dynamics — Diamond Municipal Solutions” 


USER INFORMATION * ACCESS INFORMATION _ 
| New User / Change 
Date Reguested 
o 3 
— 


Department 
Position / Role 


Effective Date 
End Date (if applicable) ao 


_ ACCESS INFORMATION | 


“For ch oft the Modules listed Below, please select the level of Permission ad no S CODES [m 
which access is ee PERMISSION  — — — — granted. 


CCOMPANIESS 


Inquiry | Transactions Seear e — nee Setup r Tas 
T 5 


Financial 
Sales (AR) 


Accounts Payable E 


DO — | [5 
cnu TP 
[Property Taxation | [-] | (J E 
miy Biin ^| C] | Cl [mm mm NN 
Business Licensing | E] | 11 — a le 
Bog teensng D E A a a a 


| 
E 


a 
[- 
Tres 
HT 


For em of Ty EUnCHOnS — _ ADMINN FF ‘select the level of ONS the a a i 
which access is being granted. 
COMPANIES 


_ SPECIAL INSTRUCTIONS _ 


Soe n ES scenario that cannot be communicated Tp the above S nati | x 


CS ' m | M" AUTHORIZATION | Um E 
The Tr Suthenze he mentions User to have access ao du Diamond; as def ned 
on this form. 


NAME SIGNATURE 


User's Team Leader (Type Name): 
System Administrator (Type Name): 
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SMART Cities Challenge: PIPEDA Self-Assessment 


The Smart Cities Challenge Management Team is comprised of members of the City of Airdrie and Airdrie and Area Health Benefits 
Cooperative and will be governed by way of a formalized Partnership Agreement. The Partnership Agreement will state that any 
work done as a part of the Smart Cities Challenge will comply with PIPEDA and the Freedom of Information and Protection of Privacy 
Act of Alberta (FOIP). 


The City Manager’s Directorate at the City of Airdrie is comprised of the Mayor’s Office, the City Manager’s Office, Legislative 
Services, Information Governance and Management, and Corporate Communications. All City staff within the Mayor's Office, the 
City Manager's Office, Legislative Services and Information Governance and Management are reguired to complete the instructor 
led 3-day FOIP training course offered by Service Alberta. Further, some members of the Information Technology team have also 
completed the instructor-led 3-day FOIP training course offered by Service Alberta. Currently, one FOIP Coordinator is registered 
and taking the University of Alberta's Information Access and Protection of Privacy Certificate (IAPP) and will be granted the C/APP 
Certified designation upon completion of the program and application to the Canadian Institute of Access and Privacy Professionals 
(CIAPP). 


The governance structure for FOIP at the City of Airdrie is as follows: 


OIP Team Leac "+ Accountable for the program's success, PIA's, FOIP requests/investigations ——— 


a day operations/inquiries. 


ele _ B Accountable for FOIP. statements, PIB's, PIA' s and day- -to- day See 
: v including disclosure of information under other legislation — cum 
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Compliance Assessment Guide 


Checklist for Principle 1 — Accountability | 


No official Privacy Policy has — 
been adopted by either party. 


CofA 


You have reviewed your 
privacy policies and are 
satisfied that they are 
complete and easy to 
understand. 


PIPEDA Self Assessment 
February 2019 


Organizational 
commitment is present 
with senior management 
support, Privacy Officer 
and Office are in place. 
Bylaw is in place for FOIP 
Head. 

Personal Information 
Inventory/bank is complete 
and updated regularly. 
Risk Assessment Tools in 
terms of PIA's and Business 
System Assessments 


Formal policies require 
development. 

BSA's have been completed 
on all new technology 
acquisitions since mid-2018. 
Critical existing technology is 
currently under review with 
all existing technology to be 
reviewed by Q4 2020. 

Work is required in terms of 
ongoing assessment and 
revision. 


Processed under the provisions of the Access to Page 149 of 341 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


(BSA’s) are formalized and 
mandatory for new and 
existing technology. 
Training and education for 
City staff is in place and 
mandatory. Specific topic 
information is provided to 
business units upon 
request and to Team 
Leaders at the FOIP Head’s 
discretion. 

Breach and incident 
management response 
protocols have been 
drafted and will be 
presented to senior 
management in 2019. 
Service provider 
management is 
accomplished 
contractually. 

External communication 
occurs and the City is 
diligent in the use of FOIP 
statements. 

FOIP process is formalized 
and well understood within 
Legislative Services. FOIP 
process is taught to and 
understood by City 
employees. Legislative 


PIPEDA Self Assessment 
February 2019 
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You have clearly delineated 
who, within your 
organization, is responsible 
for privacy governance and 
management. 


You have privacy policies 
and practices that apply to 
the personal information of 
your employees as well as 
that of your customers. 


Your privacy framework 
clearly articulates that you 
will be responsible for all 
personal information you 
hold or control, including 
information which has been 
transferred to a third party 


PIPEDA Self Assessment 
February 2019 


Services walks City staff 
through the process upon 
receipt of a FOIP request or 
OIPC inquiry. 


Clearly defined privacy 
governance and 
management. 
Information posted to 
City’s intranet. - 

FOIP Head, Coordinator 
and Privacy Officers are in 
place. 

Privacy is overseen by the 
Legislative Services unit. 


CofA 


Practices are in place but 
not all are formalized in 
documentation. 

Privacy is addressed within 
the City’s formalized 
Corporate Information 
Governance Framework. 


CofA 


The City’s formalized 
Corporate Information 
Governance Framework 
together with training and 
education articulate 
responsibility. 


Specific training on data 
ownership, contractors and the 
concepts of custody and control 
has been presented to specific 
business units, Team Leaders, 

Managers and Directors. 
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[for processing | 


You have appointed at least 
one person to be responsible Airdrie has designated a 
for the organization’s overall FOIP Head as required 
compliance with PIPEDA. under FOIP by bylaw. 
CofA FOIP online training through 
e City staff are provided with | Service Alberta advises 
You have directed staff information on the FOIP employees to always consult 
through policy, procedure or Head during training. with the FOIP Coordinator when - 
training to provide the name, » FOIP statements are used | collecting personal information 
address and phone number of when personal information | in order to ensure any necessary 
the PIPEDA contact person is being collected. FOIP notification is utilized. 
to individuals when statements articulate the 
requested. title, address and phone 
number of the contact 
person. 


You use contractual CofA 

agreements to ensure a e Depending on the type of 
comparable level of privacy information/contract, 
protection is offered to varying degrees of 
personal information while it information about FOIP and 
is in the custody of a third contractor responsibility is 


party for processing. provided. 


CofA 

e Whenever personal 
information is 
required/requested by the 
City, a FOIP statement must 
be included within the 


Your privacy framework 
addresses the principle of 
"identifying purpose" 
regarding personal 
information. 


PIPEDA Self Assessment 5 
February 2019 | 
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Your privacy framework 
addresses the principle of 
“consent” regarding personal 
information. 


Your privacy framework 
addresses the principle of 
“limiting collection” of 
personal information. 


PIPEDA Self Assessment 
February 2019 
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request identifying the 
purpose for which the 
personal information is 
being collected. 


CofA 


Business units using 
personal information are 
well informed on the 
principle of consent. 

FOIP online training through 
Service Alberta identifies for 
employees that consent is 
not one of the recognized 
collection authorities under 
FOIP and that another 
authority must exist in order 
to collect personal 
information. 


CofA 


Training and education 
reinforce the purpose of 
“limiting collection” of 
personal information to that 
that is required/needed for 
a City service or program. 
Personal information that 
falls into the category of 
“nice to have” is not 
permitted. 

Legislative Services’ review 
of FOIP statements 


CofA 
e Training and education 
reinforce the purpose of 
“limiting use, disclosure and 
retention” of personal 
information. 
Business units that handle 
personal information ona 
routine basis are clear on 
this principle. In some 
instances, specific flow 
charts have been created to 
assist staff with 
administering this principle 
when dealing with the public 
(e.g., Building Inspections). 
CofA 
The Corporate Information 
Governance Framework 
outlines the responsibility of 
staff to ensure the accuracy 
Your privacy framework of personal information. 
addresses the principle of This corporate document is 
“accuracy” regarding reinforced through 
personal information. education and training. 
Starting in Q1 2019 new 
employees learn about the 
Corporate Information 
Governance Framework and 
this principle during 


Your privacy framework 
addresses the principle of 
"limiting use, disclosure and 
retention” of personal 
information. 


PIPEDA Self Assessment 
February 2019 
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Your privacy framework 
addresses the principle of 
“safeguards” with respect to 
personal information. 


Your privacy framework 
addresses the principle of 
“openness” regarding 
personal information. 


PIPEDA Self Assessment 
February 2019 
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The Corporate Information 
Governance Framework 
outlines the “safeguards” 
required when handling 
personal information. 

This principle is reinforced 
as a part of mandatory 
education and training. 
FOIP online training through 
Service Alberta addresses 
physical, administrative and 
technical safeguards. 
Further, access to personal 
information is restricted 
through technology to staff 
who need access to such 
information in the 
performance of their duties. 


A privacy policy is currently 
under development and 
should be in place by the 
end of June 2019. 

This work is underway with 
the Corporate Information 
Governance Framework 
being released in mid 2018. 
A number of FOIP pieces still 
require development. 


Your privacy framework 
addresses the principle of 
“Individual access” regarding 
personal information. 


Your privacy framework 
addresses the principle of 
“challenging compliance” 
regarding personal 
information. | 


You have communicated 
information related to 
personal information 
handling policies, procedures 
and practices to staff. 


| You have trained staff | 


PIPEDA Self Assessment 
February 2019 


CofA 

e Mandatory training and 
education cover the 
principle of "individual 
access." This relates not 
only to customers of the City 
but also its staff. 

CofA 

e Mandatory training and 
education address the 
principle of "challenging 
compliance." Staff are 
advised that any questions 
regarding the handling of 
personal information are 
directed to the responsible 
business unit and FOIP 
office. 

CofA 

e The City’s Corporate 
Information Governance 
Framework articulates the 
handling of personal 
information. All staff were 
educated on the new 
Framework in 2018. 
City staff are reguired to 
complete mandatory online 
FOIP training through 
Service Alberta. 
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regarding the protection of 
personal information by 
informing them of 
organizational privacy 
policies, procedures and best 
practices. 


You have the means in place 
to identify which of your 
staff should be trained in 
privacy, including new staff 
and refresher training of 
existing staff. 


PIPEDA Self Assessment 
February 2019 
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The City’s Corporate 
Information Governance 
Framework articulates the 
handling of personal 
information. All staff were 
trained on the new 
Framework in 2018. The 
Framework is also covered 
as a part of orientation once 
the employee has been with 
the City for approximately 
one month. 
City staff are required to 
complete mandatory online 
FOIP training through 
Service Alberta. 
Specialized training is 
provided to those business 
units who manage personal 
information on a regular 
basis. 

CofA 
All staff are required to 
attend mandatory online 
FOIP training through 
Service Alberta. 
Staff attendance is managed 
through the City’s Human 
Resources system (Avanti). 
At this time, a formalized 
refresher program has not 
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CofA 
information is available on 
| the website. 
You have developed FOIP statements are used 
documentation to explain routinely. 
your personal information Other than information 
protection policies and provided by the Province of 
procedures to customers and Alberta, the City has not 
the general public. created separate 
documentation explaining 
the City’s protection policies 
and procedures. 


Supplemental Assessment for Federal Works, Undertakings or Businesses: 


Checklist for Principle 2 — Identifying Purposes 


You identify why you are SONA 
pd FOIP statements are e The City is currently working 

collecting personal 

| routinely used when to have a standardized FOIP 
information at or before the . 
ti Te collecting personal message put onto City 

M MEME information. The FOIP phones to address collection 
PIPEDA Self Assessment 11 
February 2019 
Processed under the provisions of the Access to Page 158 of 341 


Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


You have documented your 
purpose(s) for collecting 
personal information. 


You have notified clients and 
customers of new purposes 
for which you will use 
information if they weren’t 
identified at the time 
information was collected. 


You seek the consent of 
clients and customers before 
using information for any 
new purpose if required. 


You have notified clients and 
customers of the purposes 
before using or disclosing the 


PIPEDA Self Assessment 
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FOIP statements are 

routinely used when 

collecting personal 

information. The FOIP 

statement outlines the 

purpose for collection. 

CofA 
This is done through direct 
contact with the 
client/customer supported 
- by a public communications 

strategy. 


CofA 
This is done through direct 
contact with the 
client/customer supported 
by a public communications 
Strategy. Consent is 
requested. For example, 
when new services are 
added to the City’s MyNet 
portal, the client/customer 
is asked to consent to the 
new service. 

CofA 
This is done through direct 
contact with the 
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information if notification at 
the time of collection was not 
practicable. 


You have determined the 
amounts and types of 
personal information needed 
to fulfill your purpose(s). 


You have determined why 
you are collecting personal 
information and that the 


amount and types of personal 
information collected are 
reasonable in normal 
business circumstances. 


PIPEDA Self Assessment 
February 2019 
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client/customer supported 
by a public communications 
strategy. 

Wherever possible, a work 
around is used (e.g., 
unaddressed mail 
notification delivered to 
affected homes). 


This is done prior to 
implementing the collection 


through a collaborative 


process between the 
business unit and FOIP 
Office. 

The FOIP statement is 
developed from these 
discussions. 


This is done prior to 
implementing the collection 
through a collaborative 
process between the 
business unit and FOIP 
Office. 

Personal information 
collected is kept to a bare 
minimum. 

The FOIP statement is 
developed from these 
discussions. 
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You have distinguished 
between essential 
information (required for 
primary business purposes) 
and non-essential 
information (voluntary 
information which facilitates 
use for secondary purposes). 


You have identified non- 
essential information as 
voluntary and have provided 
staff with information on 
how to proceed when clients 
and customers opt out of 
secondary uses. 


PIPEDA Self Assessment 
February 2019 


CofA 

e This is done prior to 
implementing the collection 
through a collaborative 
process between the 
business unit and FOIP 
Office. 
Personal information 

. collected is kept to a bare 

minimum. The collection of 
non-essential information is 
discouraged. 
The FOIP statement is 
developed from these 
discussions. 

CofA 

e The collection of non- 
essential information is 
discouraged. Business units 
recognize any information 
outside of essential 
information is voluntary. 
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You obtain customer consent 
for any collection, use or 
disclosure of personal 
information. 


If you don’t obtain customer 
consent for the collection, 
use and disclosure of 
personal information, you 
have determined that it is not 
required under s.7 of 
PIPEDA. 


You make reasonable efforts 
to ensure that clients and 
customers are notified of the 
purposes for which personal 
information will be used or 
disclosed. 


You do not require clients 
and customers to consent to 
the collection, use or 
disclosure of personal 


PIPEDA Self Assessment 
February 2019 


FOIP statements are 
routinely used when 
collecting personal 
information. 

Often, with City services, 
collection, use and 
disclosure are dealt with 
through bylaw. 


CofA 


e Yes. 

e In those instances not 
covered by bylaw, consent is 
obtained. 


CofA 

e The City ensures it is in 
compliance with its 
governing FOIP legislation. 
FOIP does not contain 
authority to collect personal 
information based on 
consent. 

CofA 

e Yes. 

e The City ensures it is in 
compliance with its 
governing FOIP legislation. 


CofA 

e Yes. 

e The City ensures it is in 
compliance with its 
governing FOIP legislation. 
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information beyond what is 
necessary to fulfill explicitly 
specified and limited 
purposes as a condition of 
supplying a product or 
Service. 


You assess the purposes and CofA 

limit the collection, use and | Yes. 

disclosure of personal The City ensures it is in 
information when it is compliance with its 
reguired as a condition for governing FOIP legislation. 
obtaining a product or 


service. 
CofA 


Yes. 
You obtain consent through | m 
à The City ensures it is in 
lawful and fair means. nr 
compliance with its 


governing FOIP legislation. 
You allow a client or CofA 
customer to withdraw Yes, where possible. 
consent at any time subject to The City ensures it is in 
legal or contractual compliance with its 
restrictions and reasonable governing FOIP legislation. 
notice. 


Y ou inform clients and CofA 
customers of the implication Wherever possible. 
of the withdrawal of consent. 


You consider the sensitivity X CofA 
and intended use of personal e Yes. 
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information, and the e Wherever possible, 
reasonable expectations of expressed consent is 
clients and customers in obtained. 
determining which form of 

consent (implied or 

expressed) you will accept 

for the collection, use and 

disclosure of personal 

information. 


| Statement viden ctions, c 
o Met . Met | uc 
X 
This is done prior to 
You limit the amount and implementing the collection 
type of personal information through a collaborative 
you collect to what is process between the 
necessary for the identified business unit and FOIP 
purpose. Office. | 
The FOIP statement is 
developed from these 
discussions. 


CofA 


PIPEDA Self Assessment 17 
February 2019 
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CofA 
Personal Information Banks | e Yes. 
posted to the City's e Personal Information Banks 

are retained and kept up to 
date. 

CofA 

e Yes. In most instances this 
includes forms in use at 
recreation facilities and 
photo waivers by parents for 
their children. Another 
example would include 
providing designated 
emergency contact 
information. 

CofA 

e Yes. 

e Wherever possible, non- 
essential information is not 
collected. 


You have documented the 
specific types of information 
you collect along with the 
purposes for collection. 


You have documented when 
you collect information from 
sources other than the 
individual about whom it 
pertains. 


You distinguish between 
mandatory and optional 
collection of personal 
information. 


You limit your collection of 
the SIN to legally established 
purposes. 
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You do not use or disclose 
information for purposes 
beyond those for which it 
was collected, except with 
the consent of the individual 
or as required by law. 


You document new purposes 
conceived after the personal 
information is collected. 


Corporate Information 
Governance Framework, 
which includes the 
Information Governance 
and Management Policy, 


You only retain personal 
information as long as 
necessary to allow for the 
fulfillment of identified 


purposes. 
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Retention and Disposition 
Bylaw, Retention Schedule, 
and Process for Updating 
the Retention Schedule. 
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The FOIP statement is 
changed to reflect the new 
or added purpose. 


The City has a formalized 
retention process for 
physical information. The 
City adopted an Information 
Governance and 
Management Strategy in 
2015. Resourcing was 
approved starting in 2017 
with the City adopting a 
strategy to be digital by 
2022. The City is moving to 
SharePoint as a digital 
repository (where possible) 
with Gimmal as its records 
management tool. 
Implementation will start in 


19 


Corporate Information 
Governance Framework, 
which includes the 
Information Governance 
You retain personal and Management Policy, 
information used to make Retention and Disposition 
decisions about an individual Bylaw, Retention Schedule, 
long enough for the and Process for Updating 
individual to request access | the Retention Schedule. 
to it. 


Your privacy management 
framework governs the 
destruction of personal 
information, including the 
role of contractors 


Corporate Information 
Governance Framework, 
which includes the 
Information Governance 
and Management Policy, 


PIPEDA Self Assessment 
February 2019 
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2019 with an anticipated 
completion date of 2022. As 
business units are 
onboarded, digital 
information will also be 
managed and retained in 
accordance with the 
retention schedule and no 
longer. 


CofA 


Yes. 

The City ensures it is in 
compliance with its 
governing FOIP legislation 
and retention schedule. 
Compliance with these 
pieces of legislation may 
mean the City has disposed 
of personal information 
prior to an individual 
requesting access (i.e., 


personal information used 


to make a hiring decision 
has a retention of current 
plus 1 year). 


CofA 


The City’s Corporate 
Information Governance 
Framework together with 
the City’s retention schedule 
govern the destruction of 
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Retention and Disposition personal information. 

Bylaw, Retention Schedule, The City’s Corporate 

and Process for Updating information Governance 

the Retention Schedule. Framework includes a 
documented legal hold 
process to ensure that any 
information subject to a 
FOIP request, litigation, etc. 
is not destroyed. 


You take reasonable 
measures to ensure that 
personal information is 
accurate, complete and up- 
to-date prior to using the 
information to make 
decisions. 


You only update personal 
information if the process is 
necessary to fulfill the 
purposes for which the 
information was collected. 


Personal information is not 
routinely updated. It is only 
updated at the reguest of or 
with the consent from the 
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Your privacy management 
framework addresses the 
accuracy, completeness and 
currency of personal 
information which includes a 


process through which 
individuals can challenge the 
accuracy of information. 


Your privacy management 
framework specifies when 
updates are appropriate based 
on the defined purposes and 
uses of the information as 
well as the interests of the 
individual. 


Yes. 
Individuals are able to 
address the accuracy of their 
personal information with 
the business unit or the FOIP 
office. 
FOIP online training through 
Service Alberta advises 
employees that only factual 
information can be changed, 
not opinions. Any questions 
are to be directed to FOIP 
staff. 
As a part of the City's 
Corporate Information 
Governance Framework, a 
personal information 
standard is being developed 
and should be in place by 
June 2019. 

CofA | 
No formalized process is in 
place. 


You record when and where 
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key information was Yes. 
collected, including dates of The process is business unit 
corrections or updates to dependent. 
such information. IT systems provide audit 
trails for digital information. 
CofA 
e No formalized process is in 
place. 
Periodic spot-checks are 
You conduct periodic spot- conducted during normal 
checks, assessments or audits business practices and 
of information holdings and interactions with 
databases to ensure that key clients/customers. When 
information is accurate, dealing with 


complete and up-to-date. clients/customers, the 
opportunity is taken to 


ensure personal information 
is accurate, complete and 
up-to-date. 


You have adopted physical, 
technical and administrative Corporate Information e Yes. 


safeguards to protect Governance Framework, e Mandatory education and 
PIPEDA Self Assessment | 23 
February 2019 
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personal information against 
loss or theft as well as 
unauthorized access, 
disclosure, copying, use or 
modification. 


You choose security 
safeguards that are 
commensurate with the 
sensitivity of the information 
and the means used to 
transmit it. 


You protect all personal 
information regardless of the 
format in which it is held. 


PIPEDA Self Assessment 
February 2019 


which includes Information 
Security Classification and 
Handling. 


CofA 
Corporate Information 
Governance Framework, 
which includes Information 
Security Classification and 
Handling. 


CofA 
Corporate Information 
Governance Framework, 
which includes Information 
Security Classification and 
Handling. 
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training covers the need to 
safeguard personal 
information. 

Spot-checks and audits on 
physical information are not 
conducted. 


IT systems are designed and 


audited to control against 
unauthorized access. 

CofA 

e Yes. 

e Mandatory education and 
training covers the need to 
choose security safeguards 
commensurate to the type 
of information. 

As the Corporate 
Information Governance 
Framework is new for City 
staff, it is in the education 
phase. Auditing for 
compliance is scheduled to 
commence in the latter part 
of 2019. 
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CofA 
Corporate Information 
You make your employees Governance Framework, 
aware of the importance of which includes Information 
maintaining the Security Classification and 
confidentiality of personal Handling. 
information. | 


You have implemented 
processes to prevent 
unauthorized access to 
personal information during 
the disposal or destruction of 
information. 


CofA 
Corporate Information 
Governance Framework, 
which includes Information 
Security Classification and 


You have implemented and 
adhere to your various 
information security policies 
and practices. 


PIPEDA Self Assessment 
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CofA 


Yes 

Mandatory education and 
training on both FOIP and 

the Corporate Information 
Governance Framework 


address the importance of 


maintaining confidentiality 
of personal information. 


CofA 


Yes. 

Information Governance and 
Management staff oversee 
the destruction of physical 
personal information as a 
part of the City's annual 
destruction. The 

destruction occurs on site by 
shredding. 

Digital destruction will 
commence in 2019 as 
business units are 
onboarded to SharePoint. 
Digital destruction processes 
will be formalized by the 

end of O2 2019. 


CofA 


Yes. 

Although processes have 
been in place, they have 
been formalized through the 
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You have established an 
information security breach 
policy and commit to 
investigating the root-cause 
of such breaches. 


You have developed and 
implemented policies and 
practices including 
appropriate safeguards for all 
uses of personal information 
outside the office. 


Handling. 


CofA 


Corporate Information 
Governance Framework, 
which includes a draft 
security breach process. 


new Corporate Information 
Governance Framework. 
implementation of the 
formal processes are 
currently being 
implemented and are 
scheduled for compliance 
auditing in late 2019. 


CofA 


Yes. 

A security breach process 
has been drafted and will be 
endorsed corporately in 
2019. 


The City had endorsed a 
formalized process for 
remote access into the City’s 
network, which prevents the 
downloading of information 
onto personal computers. 


PIPEDA Self Assessment 
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procedures related to the 
management of personal 
information available to 
individuals. 


You explain to customers 
why you collect, how you 
use and when you will 


disclose their personal 
information. 


You make information 
available to clients and 
customers regarding who 
within the organization can 
address questions or 
complaints regarding the 
handling of personal 
information. 


You make the name/title and 


address of the person 
accountable for the 


PIPEDA Self Assessment 
February 2019 


Website. 


Although there are some 
policies and procedures in 
place, they are recently 
endorsed corporately and 
have not yet been made 
available to the public. 


CofA 


Yes. 

The City routinely uses FOIP 
statements for the 
collection, use and 
disclosure of personal 
information. 

Often, City services and the 
handling of personal 
information therefor are 
captured within bylaws, 
which are posted publicly to 
the City's website. 


CofA 


Yes. 

Although personal 
information is not 
specifically addressed, 
contact information for FOIP 
is included on the City's 
website. 
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You describe to your clients 
how they can obtain access 
to or correct their personal 
information. 


You provide individuals with 

a description of what Personal Information Banks 
personal information you posted to the City’s 

hold and what you disclose website. 

to other organizations. 


CofA 

Province of Alberta, FO/P Yes 

Guidelines and Practices The City uses a standard 
process for responding to 
FOIP requests. 
A register of requests is kept 
by FOIP staff to track each 
request (includes a file 
number, applicant name, 
date received, due date, 


You have adopted policies 
and procedures for 
responding to requests for 
personal information under 
PIPEDA. 


PIPEDA Self Assessment 28 
February 2019 
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You have advised staff of the 
need to direct requests for 
access to information to the 
staff member responsible for 
processing these requests. 


You inform individuals of 
the existence, use and 
disclosure of their personal 
information on receipt of a 
written request. 


You provide individuals with 
access to personal 
information on receipt of a 
written request. 


PIPEDA Self Assessment 
February 2019 
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Online FOIP training 
through Service Alberta 
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details of request, who in 
the organization was asked 
to search for records, fees 
estimated/collected, date a 
response was provided, the 
response time (in days), the 


outcome of the request, and 


whether a request for 
review was made. 

CofA 

e Yes. 

ə Mandatory education and 
training provide staff with 
the FOIP structure at the 
City and identifies the staff 
member responsible. 
Reception staff in all 
buildings are familiar with 
the process and have FOIP 
request forms available for 
the public. 

CofA 

e Yes. 

e This is handled through the 


FOIP office within Legislative 


Services. 

CofA 

e Yes. 

e Regardless of the method of 
the request, access to 
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personal information is 
provided. Wherever 
possible, the FOIP office 
responds in a timely manner 
and outside the formalized 
FOIP process. 

CofA 

e Yes. 

e The City ensures it is in 
compliance with its 
governing FOIP legislation. 


You limit refusal to provide 
access to information to 
exceptions described in 
Section 9 of PIPEDA. 


You provide an account of 
the uses of information on 
request. 


You provide an account of 

all third parties to whom 

information has been 

disclosed (or a listing of the 

types of third parties to 

whom such information is 

generally disclosed) on 

receipt of a request for such a 

list from an individual. 

CofA 

e Yes. 

e The City ensures it is in 
compliance with its 
governing FOIP legislation, 
which requires City staff 
assist those individuals who 


You assist those individuals 
who indicate they need help 
to complete a request for 
information. 


PIPEDA Self Assessment 30 
February 2019 
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You respond to a request for 
information at minimal or no 
cost to the individual. 


You respond to a request for 
information in not more than 


30 days unless you notify the 
requestor within that time 
period of your need to extend 
the time limit for response, 
indicate the extended time 
limit and inform the 
requester of his or her right 
to complain to the OPC. 


You rely on time limit 
extensions only in cases 
where responding within the 
original 30 days would 
unreasonably interfere with 
your activities, when 
additional time is needed to 


PIPEDA Self Assessment 
February 2019 
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require assistance in 
completing a request for 
information. 

These requests for 
assistance are directed to 
FOIP staff. 


CofA 


Yes. 

The City ensures it is in 
compliance with its 
governing FOIP legislation 
and costs permitted 
thereunder. 


CofA 


Yes. 

The City ensures it is in 
compliance with its 
governing FOIP legislation, 
which stipulates time limits 
for response. 

The City uses standard letter 
templates provided by 
Service Alberta. 


CofA 


Yes. 

The City ensures it is in 
compliance with its 
governing FOIP legislation. 
The requester is provided 
with written notification in 
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conduct consultations, or the event a time extension is 
when additional time is required. 

needed to convert personal 

information to an alternative 

format. 


You provide access to CofA 

information in a format e Yes. 

which is legible and will | e The City ensures it is in 
provide an explanation of compliance with its 
abbreviations or codeson ` governing FOIP legislation. 
request from an individual. 


You advise requestors of the | CofA 


reasons for refusal and e Yes. 

recourse available to them e The City ensures it is in 
when refusing to provide compliance with its 
information. | governing FOIP legislation. 


You allow individuals to CofA 

challenge the accuracy of - e Yes. 

personal information and e The City ensures it is in 
amend information when an compliance with its 
individual demonstrates that governing FOIP legislation. 
information is inaccurate or 

incomplete. 


You forward corrected 
personal information to third 
parties who would have 
received the original 
information. 


PIPEDA Self Assessment 32 
February 2019 
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Overview 


DatumSURE is pleased to submit this proposal for services to support the City of Airdrie and the 

Airdrie & Area Health Cooperative (AAHC) in achieving its goals to win the $10 Million category of the 

Infrastructure Canada Smart Cities Competition. This proposal provides a technology plan for the 

development and administration of a “Community Operating System” (COS) or “HealthSmart Hub” . 
including; API development, management and administration, data connections, interfaces, and - 
dashboards. For the purposes of this document we will use language that assumes that datumSURE 

be selected to develop and implement this solution for AAHC. We are excited to be working with the 

City of Airdrie and the AAHC and look forward to helping them achieve their goals to create a 

healthier and more connected community. 


The Objective 


DatumSURE's technology plan proposal is a succinct technical strategy document covering 
technology, implementation, operations, support and ongoing development of the recommended 
solution. The proposal includes the following key elements or needs; 
e Need #1: Present a plan/solution for the creation of a HealthSmart Hub (Community 
Operating System) — Integration Engine, Dashboards, Front door for app development and 
integration. 


e Need #2: Visually demonstrate how the engagement, collaboration & connectivity through 


connected technologies will look. 


o Capacity to connect to externally managed applications, software and devices (ie. 


Wearables, Apps, etc.). 


o Capacity to implement (recipe book for implementation). Ability to connect and/or 
potentially integrate apps developed specifically for community (ie. licensed = 


/commercial software). 


o Integrated technologies. Apps developed for any community and integrated as core 
components (ie. custom built, open source software). 


e Need #4: Present safety & security through risk, security and privacy frameworks. 


e Need #5: Present and explain the alignment and connectedness to other community 


initiatives (ie. MyAirdrie citizen portal, Health Park, etc.). 


In addition, Datumsure is focused on ensuring that the proposal will support the following 
overarching goals; 


e Goal #1: That the solution can be replicated in other communities. 
e Goal #2: That open source technologies are utilized whenever possible. 
e Goal #3: Minimal financial strain on any municipality or it’s citizenry. 


^e Goal #4: A sustainable business model. 
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Proposal 


DatumSURE is a technology company focused on entity-centric master data integrity management 
and globally accepted data privacy goals and practices. Our overarching goals are to put data rights 
squarely into the hands of the individual, facilitate a universal view of an individual/entity, help 
organizations slow the rising cost and risk inherent in data management, and provide a way for data 
owners to legally and ethically monetize data by fixing and streamlining broken workflows. We 
believe these goals coupled with our technology and experience make us the perfect partner for 
AAHC and the development of the HealthSmart Hub. 

The HealthSmart Hub will revolutionize the way Airdrie citizens and other participating 
entities/organizations interact, share and use their data. By providing assurance around data 
provenance and integrity and empowering individuals to have control of their data, we begin to 
reform the data landscape away from data acquisition, collection, storage, etc. toward the concept of 
knowledge/insight sharing. Thereby, allowing people to use their data safely to optimize their lives 
and communities. 


The Solution 
HealthSmart Hub 


The current market transfers data from source to source, multiplying the risk and cost associated with 
administrating, storing and securing the data. According to an Experian Data Quality study this 
duplication and redundancy within data rich organizations represents a hidden cost equaling more 
than 12% in lost revenue and will reach $3.3T worldwide by 2020. Our solution mitigates these costs 

. by giving individuals, 
organizations and government 
entities applicable, appropriate 
and permissioned access to 
guery data elements and 
sources through benchmarking, 
Bl and visualization tools. In 
addition, each piece of 
information comes with a 
verified integrity and 


provenance report. Our goal is Search Oueru 


to help companies get 
“knowledge from data, not risk". 
DatumSURE will use a variety of open source technology products to develop the proposed 
HealthSmart Hub, the COS.. Essentially, we are recommending the implementation of a unigue 
municipal focused version of our Master Data Integrity Management (MDIM) platform and tools. 
Our solution leverages zero-knowledge proof principals, Hyperledger blockchain 
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ATIA - 20(1)(b 


ATIA - 20(1)(c) 


solutions and advanced database tools to create a trustless and completely secure data management 


system that maps data provenance, assures data integrity and places data rights squarely in the 
hands of the individual (e.g. Airdrie citizens and applicable entities). This data platform ensures all 
data is safely and securely directed by the individual enabling them to share insights and applicable 
data from disparate and decentralized data sources. 
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ATIA - 20(1)(c) 
SECURITY 
The primary concern of any data centric engagement is data security. Neither the HealthSmart Hub 
nor datumSURE will store any sensitive individual or entity data within their system (encrypted or 
unencrypted) 
e Data: 


o What DOES the system store? 

= We store an encrypted map of entities. 

" Proprietary metadata for the purposes of monitoring the integrity and health 
of each data source. 

o Data Sharing: 

" The system allows for the sharing of data (e.g. insights, benchmarking, data 
transfer, etc.) as directed by the data subject (e.g. citizens) or by predefined 
applicable and appropriate permissible use cases (e.g. medical emergency, 
preauthorized access) within the confines of GDPR and municipal guidelines. 

e User Authentication & Access Controls: There are many user authentication & access control 
solutions on the market. We’re recommending several potential vendors offering a multi- 
factor authentication for integration. Our proposal includes integrating one of these 
solutions. 

o Potential solutions for user authentication: 
"  AuthO 
" DigitalPersona 


= AuthAnvil 
" KeyCloak 
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GOVERNACE 
We see Datumsure as an advisor and technology partner supporting the "Smart City" governance 
structure. 


TRAINING 

DatumSURE will provide applicable and appropriate training to meet RFP requirements. In addition, 
we will provide consultative guidance and support to Airdrie in developing strategies for increasing 
community interaction with the tools and COS modules. 
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Conclusion 


We're excited to support the city of Airdrie and the Airdrie & Area Health Cooperative (AAHC) in this 
exciting project to help Airdrie become Canada's healthiest community. We believe that our 
technology, mission and corporate philosophy match perfectly within the scope of this project and 
specifically in helping Airdrie and the AAHC empower Airdrie's citizens through the creation of a 
“Community Operating System” (COS)/“HealthSmart Hub.” We look forward to continuing to support 
this effort and hope you will trust us to help accomplish this goal. 


datumSURE at 


r by telephone at MEM 


If you have questions on this proposal, feel free to contact 
your convenience by email a 
We look forward to working with you and helping you succeed. 


Thank you, 
| A RE 
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TEC E EL H N O L O G Y Enterprise Intelligence and Smart Cities 


#2, 23 East Lake Crescent NE Airdrie, Alberta, Canada T4A 2H5 https://oasistechnology.ca 
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— PROJECT ESTIMATE 
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THE PROJECT 


As part of an ongoing pitch effort, the city of Airdrie (and by extension Oasis) is seeking a 
partner to work on a healthcare Focussed, smart city initiative. The pitch itself is part of the 
federal government's “Smart Tech Fund” which aims to create new pockets of innovation 
across the country. Asa city, Airdrie is poised to embrace shifting technology paradigms, 
marrying blockchain with healthcare to create transparency, empower patients (and their 
data), as well as generate both new potential revenue but also bold new employment / 
business opportunities for the city and province. | 
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Oasis would be engaged to complete the following work: 


@ Oasis Technology is seeking preliminary estimates for an engagement to assist with a User 
Experience (UX) assessment and design of a MVP Web & Mobile application. | 


@ Elevate and identify security best practices, from a user experience perspective, and 
provide recommendations based on findings. 
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(BY EXPERIENCE 


cm 


Fully design the experience 


Fully design the experience through robust documentation that 
will guide thee development process and ensure client alignment 


FAU Hon: 
Architecture. | 


Define the way an interface 
will function through both 
low-fidelity visual | 
representations and detailed 
Functional requirements 


e Wireframes 
* Functional Designs 


Visual Design & 
Motion Graphics 


Define the visual style and 
motion of the experience 
and apply it to all interface 
states and customer 
touchpoints 


* Creative concepts 
* Extended visual designs 
e Motion Graphics 


e Style Guide 
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Prototype. 
Development 


Develop a representation of 
the experience that can be 
tested with end users 
ranging from a lo-fi paper 
printout to a nearly 
Functioning user interface 


* Lo-fi prototypes 


e Hi-fi Prototypes 


Uaseability 
Testing 


Identify opportunities to 
improve an experience by 
observing an end user's 
attempt to complete 
common tasks 


* Concept Testing 
s Integrated design validation 


* Prototype testing 
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NL 
Planning 


Document a vision and 
roadmap for content, 
including themes, topics, 
voice, tone and content KPIs 


s Content matrix 
e Editorial calendar 
e Editorial style guide 


e Content migration plan 


INNOVATION METHODOLO 
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INNOVATION METHODOLOGY 


iterate & Optimise 


RESEARCH & IDEATION | EXPERIMENT 


De-risk focus of innovation De-risk Ul expression, ROI, and De-risk timeline, cost & delivery De-risk hiddden conversion 
pU a ore St trchnical and data barriers © efficiency | | — barriers and design flaws 
-Byunderstanding: — . Through: | E Through: dag oe BY | Through: 
+ Business objectivess ions . c Ul experiments and testing -`e Agile development 2505 0.8 Usability testing 
« Userneeds and improvement » Technical POCS .: y (Uo Pre-vetted requirements | | + A/B testing 
+. Common processes and tasks | E | | 
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PROJECT INVESTMENT 
AND TALENT ESTIMATES 
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TALENT INVESTMENT - INITIAL 5 WEEKS 


NAME AND ROLE 


Account Manager As Needed 


Project Manager 1 

UX Researchers 2 

UX Designer 1 

Business Analyst 1 

Subject Matter Expert 2 
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TALENT INVESTMENT - YEAR ONE 


NAME AND ROLE 


Account Manager | As Needed 
Project Manager 1 
UX Researchers 2 
UX Designer 1 
Business Analyst 1 
6 IOS Developers 6 
6 Full Stack Engineers 6 
6 Android Developers 6 
Subject Matter Expert 8 
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TALENT INVESTMENT - YEAR TWO 


NAME AND ROLE 
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— PROJECT INVESTMENT 


PROJECT PHASE ESTIMATED EFFORT ... ESTIMATED INVESTMENT - 


VERSION 1.0 MVP m A WEAR SS E Eure | $3,564,000 
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https://oasistechnology.ca 


Meu #2, 23 East Lake Crescent NE Airdrie, Alberta, Canada T4A 2H5 
Phone Main: +1.403.912.9129 Toll Free: +1.800.318.1441 En Francais: +1.877.318.1448 
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CHAPTER 2: PERFORMANCE MEASUREMENT... 


CHAPTER 7: DATA AND PRIVACY sse 
CHAPTER. OEN OA god Sy diete edens 


APPENDIX A: LETTERS OF SUPPORT 
APPENDIX B: FINANCIAL DOCUMENTS 
APPENDIX C:YOUTUBE VIDEO TRANSCRIPTS 


APPENDIX D: PRELIMINARY PRIVACY IMPACT 
ASSESSMENT DOCUMENTS AND LETTER 
FROM THE OFFICE OF THE INFORMATION 
AND PRIVACY COMMISSIONER 
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IRDRIE : Airdrie & Area 
A | BARIE » Health Cooperative 


Health is a hot topic in Airdrie. Research shows that 
focusing on preventative health has a much stronger 
impact in keeping Canadians healthy than access 

to medical care alone (Source: Canadian Medical 
Association). The Smart Cities Challenge and our 
focus on preventative health will help us to achieve our 
goal of making Airdrie Canada’s healthiest community. 
And, we will be able to share our approach, technology 
and learnings through a comprehensive program that 
can be replicated to have the same impact in all other 
communities across Canada. 


We are a community with two partners, the City 

of Airdrie and Airdrie & Area Health Cooperative, 
who are committed to supporting our community to 
become healthier and are taking tangible actions to 
make it a reality. 


OUR PROPOSAL 


The $10 million from the Smart Cities Challenge 

will utilize data and connected technologies that will 
support our goal of increasing healthy life expectancy 
by 3+ years over 5 years and ultimately change the lives 
of every resident in our community. Our proposal 
includes: 


1. Optimizing open data and connected technologies. 


2. Building the HealthSmart Community Operating 
System (COS) — a community connector that 
facilitates data to be exchanged between individuals, 
organizations and businesses. 
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3. Developing the Smart Service Inventory — a smart 
navigation system allowing users to know what 
services are available locally, how to access, why 
to access, and why it is best suited to them based 
on their own individual profiles and will mobilize 
community information regarding the social deter- 
minants of health. 


4.Connecting the COS with several technologies that 
are outside of the Smart Cities Challenge through 
an application programming interface. Examples of 
other technologies include the Community Health 
Information Resource Platform (a partnership 
between the Airdrie & Area Health Cooperative and 
Alberta Health Services) to support the outcome 
measures important in achieving our Challenge 
Statement, activity and fitness tracking (e.g., FitBit), 
micro-credentialing and eMental Health. 


5. Connecting users to the HealthSmart Technology 
through the MyAirdrie Portal, native mobile apps 
and kiosks offering access to all residents around the 
city. 

HealthSmart Airdrie will connect the work we are 

doing to change the culture of our community to one 

that focuses on health, by implementing Blue Zones. 

By optimizing our environment - those settings where 

we live, work, and play, which influence our behaviour 

— we can make the healthy choice the easy choice so 

that we naturally adopt healthy behaviours. 


(Source: Becoming a Blue Zones Community Handout - 


Blue Zones Project). 
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To build a technology that meets the needs of residents 
and gives them easy access to healthy choices, we will: 


e Focus on the social determinants of health and 
connecting the technology to meet the current and 
evolving needs of residents — Chapter 1: Vision. 


e Measure well-being through Community Health to 
provide indicators for individuals to assess how they 


are doing in relation to these determinants — Chapter _ 


2: Performance Measurement. 


e Provide a variety of opportunities for stakeholder 
input into the development and implementation — 


Chapter 6: Engagement. 


+ Implement a diverse and inclusive approach to stake- 
holder identification, involvement and engagement 
— Chapter 6: Engagement. 


e Ensure privacy and security of data is core to the 
project — Chapter 4: Technology and 
Chapter 7: Privacy and Data 
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The implementation of our Smart Cities Challenge 
program will include best practices in project manage- 
ment, the stakeholder engagement methodology from 
the International Association of Public Participation, a 
detailed data management, privacy and security plan, 
well defined governance and supporting structures, 
sound contractual agreements and the identification of 
risks and mitigation strategies in a risk register. 


The Smart Cities Challenge allows us to engage 
community residents and build a technology over 
the next five years, providing Airdrie with a unique 
opportunity to have a real impact on peoples lives. 
Ultimately, increasing healthy life expectancy by 3+ 
years Over 5 years. 


Airdrie is excited to be the proving ground for creating 
a technology that enables our residents to achieve 
better health outcomes. We are even more excited 

to share the learnings of our journey with the rest of 
Canada. Together we can create a country of healthy, 


resilient, engaged and supportive communities. 
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It's the year 2025. Your destination, the city of Airdrie. 
A place you've heard of as having a small-town feel and 
big city amenities and an innovative and entrepreneur- 
ial spirit, but something has changed. You experience 

a city like no other; new communities are planned 
with connection in mind — pathways, shopping and 
recreation are in walking distance no matter where you 
are and access to healthy choices are easy. 


: You meet Brandon. Five years ago, he didn't know 

. how to add more vegetables to his family's meal 

< and how to do it on a budget. Through 
 HealthSmart Airdrie, he accessed cooking 
classes for picky eaters, recipe ideas 
from local businesses and budgeting 

- resources through his local bank. Today, 

adding vegetables to meals is easy and 
Brandon has paid off his loans. 


-You decide to try out HealthSmart 
-Airdrie and create a single sign-on, 
- giving you access to local services. You 
- find Don and Marg. They were looking to 
- meet more people in the community by - 
-sharing their favorite game, crokinole, but 
were having a difficult time getting out because 
: they're not able to drive. They use HealthSmart 
Airdrie fo set up a community group, schedule crokinole 
-. games and book a shared ride service. They are now in 
— charge of Airdrie’s first Crokinole Club. 


How did we get there? Our community leveraged the 
$10 million Smart Cities Challenge (SCC) award to 
work together to create a connected community — one 
where people connect with meaningful, individual- 
ized, local information, resources and expertise that 
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You can connect to community organizations for men- 
tal health support, employment, affordable housing and 
senior networks, and services like continuing education 
classes, budgeting tools and transportation through 
your phone, computer or a community kiosk using 
HealthSmart Airdrie. Everyone you meet understands 
that health is more than physical and mental health; 


health and connection are a way of living in Airdrie. 


You also meet Sam. She was having trouble with 
school and was having a hard time dealing with 
her stress. Through HealthSmart Airdrie, she- 
accessed counselling services, found a tutor 
to help her with her homework and joined — 
the Airdrie youth group. She is now getting — 
good grades and leads activities- 
for teens in Airdrie. - 


2d 


Fr Through your search, you also find H&W 
Airdrie Inc., a company that supports 
people new to the community. Before … 

HealthSmart Airdrie, H&W had to conduct. 
various searches and send their clients to : 
multiple organizations to access community - 
services. Today, H&W can use HealthSmart © 
Airdrie to better plan its services and access local : 
services like doctors, housing and employment for its - 


clients, all in one place. You schedule an appointment with = 


them to learn how to become part of the Airdrie community. … 


helps residents make better, more informed choices 
about their overall well-being and the health of their 
families. By working together and engaging everyone 
in Airdrie, we created a health and well-being-focused 
movement in our community, where everyone, 
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including Airdries most vulnerable, feel welcome, safe, 
are supported and know that they belong. 


Bue Mat aad PA Pe Reet NR À à 
BY ENGAGING AND SECURING THE PARTICIPA- 
| TION OF ALL IN THE COMMUNITY TO CREATE A 
Y HEALTHY CULTURE THAT IMPROVES 
SOCIAL ECONOMIC, PHYSICAL AND HEALTH 
CARE ENVIRONMENTS AND INDIVIDUAL 
à CHARACTERISTICS AND BEHAVIOURS, SO 


INCREASED BY 3+ YEA 


AR 
5 YEARS. 
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OUR VISION: 
HOW ARE WE GOING TO ACHIEVE IT 


Airdries Challenge Statement is big. It commits to 
including all individuals, families and organizations 
in Airdrie and area to create an environment based on 
the social determinants of health (SDOH) - strategies 
that help connect the dots between people in the 
community with the policies that guide decisions and 
actions. It includes sustained community engagement 
and involvement to achieve the goal of increasing 
overall healthy life expectancy in Airdrie by 3+ years 
over 5 years. 


Taking on this Challenge Statement will have impacts 
both provincially and nationally. Our success will 

be transformative in Airdrie, with learnings that can 
be applied across all communities in Canada. It will 

_ require a connected, caring community that supports 
everyone, embraces diversity and builds a culture 
where everyone can have a role in becoming Canadas 
healthiest community. And we know we can get there. 
Our vision is possible. Our proposal outlines three real 
and actionable ways to achieve this big goal: 


1. We are a community with two partners, the City of 
Airdrie (CoA) and Airdrie & Area Health Cooper- 
ative (AAHC). We are uniquely positioned to focus 


on optimizing the technology opportunity presented 
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THIEST COMMUNITY, | 


by the SCC and to engage the community in an 
intentional journey for health; 


2. Our focus on health is underpinned by existing 
leading practices for community health; and 


3.Our technology focus capitalizes on the SCC oppor- 
tunity, by optimizing capacity within the CoA and 
AAHC and its partners to create a unigue capability 
to connect individuals in the community and create 
an environment for smart community information to 
monitor outcomes toward our Challenge Statement. 


STRONG en GETH HER TO MAKE 
A BETTER TOMORROW FOR ALL 


Airdrie is a fast-growing and changing city. Today, 
we are 68,000 strong, with a diverse population that 
includes young families and an increasing senior 
population. 


We are one of the fastest growing medium-sized 
communities in Canada with a projected population 
of 100,000 within the next ten years. Many view 
Airdrie as a prosperous city, with an average income of 
$102,000 and many services for a city of its size. 


Although Airdrie has many strengths, our community 
also has some significant challenges. The current 
economic climate has created unemployment, and 

a lack of full-time, good paying jobs amid a slow 


economic recovery. 


We have additional challenges that need to be 
addressed if we are to reach our vision: 


e Housing affordability. 


e Lack of supports for youth mental health and service 
options for individuals of all ages. Stressors in the 
community are also evident regarding high rates of 
domestic violence. 


e Lack of information regarding available services. 
Orienting newcomers to the vast array of services 
and programs available in Airdrie is a challenge in 
our growing community. 


e Silos for service delivery. 


e A desire for information enabling healthier 
individuals. 
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GENDER eS 
Male: 50% Female:50% 


|?» AGE 
0-14: 25 15-24: 11 25-64: 58 64-74: 5 75+: 2 MEDIAN AGE:33 


MARITAL STATUS 
Single: 28 Common Law: 12 Married: 54 Divorced/separated/Widowed: 11 


LANGUAGES SPOKEN AT HOME 
English: 92 French: 1 


TOP NON-OFFICIAL LANGUAGES 
y Tagalog/Spanish/Punjabi 


Aboriginal People: 5 | Ud Employed:81 Renters:17 


Owners:83 


Visible Minorities: 13 


Immigrants:12 


Figure 1.1 shows what Airdrie would look like if we were a village of 100 people. Source: Statistics Canada, 2016 Census of Population. 
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For the past five years, our community has repeatedly 
expressed a desire for a hospital. After many discus- 
sions, the Alberta government responded that hospital 
services are only about 25 minutes away in Calgary, 
and therefore a hospital is not warranted in Airdrie. 
The Minister of Health encouraged our community to 
look at health differently and stated in December 2015, 
“I am supportive of a grassroots approach to health.” 


This statement became the catalyst to a unique com- 
munity opportunity in Airdrie: 


1. We have a community vision focused on health; 


namely, to own our own health, becoming Canadas 
healthiest community! 


2. We have an organization, AAHC, focused solely on 
being a catalyst for a healthy community. 


3. We have a municipality, the CoA, embracing this . 


vision, along with the Mayor's recent Proclamation 
that 2019 will be the Year for Healthy Living. 
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The CoA and AAHC are bringing the best of our two 
organizations toward the Challenge Statement and this 
proposal: 


e The CoA is the lead organization for the SCC and 
the lead for the technology development. 


* AAHC is a partner in the technology development 
and will be managing the community health 
engagement plan and measurement of outcomes 
for community health in a parallel manner to SCC 
technology developments. 


BEST PRACTICE: 
There are several leading practice documents to guide 
work in Airdrie to mobilize our vision for community 


health: 


« An overview article from BC cuti Communities 
it 2) provides clear 


E Ch EVE TT HET’ STUD 2378430 
(htt pu fbchealthvcommunitic 


direction: 


a. The fundamental core value of the healthy 
communities approach is capacity building and 
empowerment of individuals, organizations and 
communities. 


b. The healthy communities approach needs to 
address multiple determinants of health and 
include five essential strategies: community 
engagement, multi-sectoral collaboration, 
political commitment, healthy public policy, 
and asset -based community development. 


«. The Chief Public Health Officers Report on the State 
of Public Health in Canada 2017 published by Public 
Health Agency of Canada focused on designing 
healthy living. The report ends with a call to action 
with specific focus on designing communities for 
Canadians to take charge of their own health. 


The action plan for community health sponsored by 
AAHC incorporates concepts from the above docu- 
ments (attached to the AAHC letter of support). 


Realizing the community vision requires intentional 
and large-scale community engagement, AAHC has 
chosen the Blue Zones Project from the USA to bring 
their experience and methodologies for this city-wide 
community process. They also bring measurement 
expertise and the ability to provide predictive out- 
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comes regarding system-wide reduction in health care 
costs and projected impacts on life expectancy. 


AAHC is building on this expertise with Alberta part- 
ners, including Alberta Blue Cross, for the well-being 
measure, to create a "made in Canada" measurement 
system. AAHC has also partnered with Alberta 
Health Services to create focused health policies and 
develop the Community Health Information Resource 
Platform (CHIRP - being developed in partnership 
with Alberta Health Services and the AAHC using 

in-kind contributions) to create dashboards with 
health outcome data. 


Blue Zones also brings unique expertise in creating 
healthy living environments by collaborating with 
local developers, the CoA and Alberta Health Services 
to develop comprehensive built environment policies 
aimed at creating communities for healthy living. 


The overall initiative, “Healthiest Airdrie, powered by 
a Blue Zones Collaborative’, will be the most com- 
prehensive community engagement this community 
has experienced. It will begin April/May 2019 with - 
an eight-month discovery process to plan communi- 
ty-specific engagement led by locally hired facilitators. 
Following this, there will be two years of structured 
engagement with the community. As outlined in 
Chapter 6: Engagement, there will be connections 
between stakeholder engagement related to technology 
development, Blue Zones and initiatives focused on 
community health and SDOH. 


Fundamental to success with strategies for community 
health —as well as strategies that continue to meet 
residents needs in new ways —is to create a digitally 
connected and enabled community. The ability to 
inform and monitor the success of community health 
engagement reguires smart community information, 
hence the importance of the HealthSmart Technology. 


HEALTHSMART TECHNOLOGY: 

THE HEART OF AIRDRIE'S 

SMART CITIES CHALLENGE PROPOSAL 
HealthSmart Technology will be a community 
connector - facilitating data to be exchanged between 
individuals, health and social service organizations, 
community not-for-profits, businesses, local, regional, 


provincial and federal government departments. It 


Page 212 of 341 


will be extremely versatile and will be used to allow 
individuals to access a wide variety of data. 


The underlying technology for the proposed 
HealthSmart Community Operating System (COS) 

is being used by many industries, including the 

highly regulated finance and insurance industries. 
The existing technology is expensive, well beyond 

the means of most municipal governments and is not 
presently designed to meet the more stringent privacy 
and risk legislation that municipal governments are 
held to. The creation of this technology with support 
from the SCC will allow local governments to become 
early adopters. 


Airdries proposal to create a Smart Service Inventory 
(SSI - a smart navigation system allowing users : 

to know what services are available locally, how to 
access, why to access, and why it is best suited to them 
based on their own individual profiles) will mobilize 
community information regarding the SDOH. By 
creating a system that allows for immediate access to 
personalized, verified, secure information, Airdrie 
and area residents will make meaningful connections 
to local resources, services, professionals, and social 
connections to help our residents make better, more 
informed decisions about their health and the health of 
their families. 


HealthSmart Technology will also connect with the 
CHIRP. The goal is to create smart community infor- 
mation to support the outcome measures important in 
achieving the Challenge Statement. 


At the foundation of our HealthSmart Technology, 

is learning from our benchmarking of other cities 

that have implemented smart technologies. Our 
benchmarking has shown that by focusing on the 
needs of a community, such as the goal to be a healthy 
city, technology is an enabler for community good and 
a significant catalyst for ongoing sustainability. 


DETERMINANTS OF HEALTH: POWERED 
BY BOTH COMMUNITY HEALTH 
ENGAGEMENT AND TECHNOLOGY 

Our submission focuses on SDOH, given their im- 


portance on impacting the community vision and the 
Challenge Statement. According to the World Health 


Organization, SDOH “are the conditions in which 
people are born, grow, work, live, and age, and the 
wider set of forces and systems shaping the conditions 


of daily life” 


The health of an individual, group, organization 

and the overall community is tied directly to the 
determinants of health. The determinants of health 
include the social, economic, physical and health care 
environments of a community and individual char- 
acteristics and behaviours of those in a community. 
For our project, we have decided to focus on eight 
determinants or factors for healthy living. (Figure 1.2) 


The Community Health measures of well-being 

will provide indicators for individuals to assess how 
they are doing in relation to these determinants. 
Information from developing the SSI and monitoring 
usage trends will help the community understand the 
strengths and gaps related to SDOH, allowing us to 
improve health overall. 


HOUSING 


RROUNDINGS 


| FAMILY, FRIENI 
& COMMUNI 


o 


MONEY E 
& RESOURCES ES 


Figure 1.2 shows we are focusing on eight social determinants 
of health — housing, work, food, surroundings, family, friend & 
community, money & resources, transportation, 

and education & skills. 


By focusing on health, we can build a smart commu- 


nity through which all environments and stakeholders 
are digitally engaged and enabled through open data, 


connected technologies and measurement. Open data 


and connected technologies allow for measurement 
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specific to individuals, families, need-based groups and 
the community and subsequently provide actionable 
insights. By focusing on health determinants, we 

can collectively focus on improving the lives of our 
residents and identify the real issues that need to be 
addressed in our community. Health is the common 
denominator. 


PROGRESS TOWARDS OUTCOMES 
ACHIEVED DURING THE FINALIST PHASE 


Over our comprehensive proposal development stage, 

we were able to flesh out the HealthSmart Technology 
‘more thoroughly to better understand how it can 

connect to other platforms and resources, the require- 


D. 


ments for single sign-on, security and privacy, and 
how the technology will work, connect to and support 
our Blue Zones program. We were also able to conduct 
more research into the understanding and needs of 
our community. 


During the proposal development stage, the Smart 
Cities Team attended AirdrieFest (a local festival aimed 
at promoting all that Airdrie has to offer), developed 
the HealthSmart Airdrie website, hosted an open 
house, sent out a survey, sent out email updates, and 
posted regularly on social media to ask Airdrie and 
area residents about health and what matters to them. 
Details of our findings can be found in Chapter 6: 
Engagement. 


We created “HealthSmart Airdrie” This includes a 
brand we have rolled out to the community 

Mum M MA social media and a website 
(https;//healthsmartairdrie.ca/). Our plan is to 
continue to use this branik to engage Airdrie and 

area residents in the SDOH, and the role they play 

in increasing individual and community well-being. 
Our aim is to increase understanding around SDOH, 
which would not only enable improved individual and 
population health, but also advance health equity. We 
are also working to “create social and physical envi- 
ronments that promote good health for all? (Source: 


City Council demonstrated their support for the health 
movement with a $1.5 million contribution to bring 
the Blue Zones program to Airdrie. The movement, 
policy changes, and well-being measurement tools / 
data, which comes from the Blue Zones initiative, will 
help advance our Challenge Statement. 


Recently City staff have been in discussions with major 
telecommunication carriers to advance fibre and 
wireless implementation strategies to get high speed 
fibre to every home and business in Airdrie and to 
expand 5G connectivity by the end of 2020. The CoA 
is in a good position to build upon partnerships to 
improve upon the services we deliver to our residents. 
This will improve technology access for all Airdrie 
residents. 
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Tee City of of Aude i eg implementing smart ci cy initiatives i in a 2007 0 to collect datat to o better andn more re efficiently | 
â provides services to residents. - = _ l m noL a E Mu c M tor nin wegitstt ie 


j | 2007- 2009 - - Network connectivity at intersections E _ v E m UR 


2007- ane A Weather Stations report rood conditions allowing for municipal business units to obtain real time data reducing f fuel 


and resource costs 2 


2008 - Centralized aiministiation of all iírigatión system for water conservation: p 


[en 2 - Multi-Response Vehicle supports a multi-agency approach to assisting citizens in ‘emergency situations - 


| 2014 - Flowpoint bulk water monitoring and distribution 


i 2017 - Civic property protections 


| tions 


* 2015 - Remote monitoring and management of waste and water 


| 2014-18 — CP Rail monitoring provides data to emergency responders 
; 2015 - UAV/Drone program to collect data for fire investigations, emergency operations and infrastructure inspections 


¢ 2017 — Broadband network infrastructure upgrade at intersections to support wireless communications, to collect road condition 
data, intersection pre-emption for emergency response vehicles, signal controls and timing, traffic count data 


* 2018 - Municipal Enforcement in-car video offload to ensure chain of custody of video and audio footage from officer interac- 


* 2019 - Telus will be connecting every home and business in Airdrie to the PureFibre network by the end of 2020 


with 5G expansion future opportunities. 


HOW OTHER COMMUNITIES CAN BENEFIT 
All local governments can benefit from the creation of 
HealthSmart Technology. All communities, regardless 
of size, are struggling with sharing relevant infor- 
mation about local resources to help their residents, 
and the larger the community the more difficult it 
becomes. 


There are three ways that other communities can 
benefit from the SCC investment in Airdrie: 


1. The investment in technology (Chapter 4: Technol- 
ogy) will result in components that can be replicated 
in other communities. 


a. The SSI will be an application that can be used in 
other communities. 


b. The COS will be created with open technology 
for use by other municipalities in connecting data 
and systems. Ihe more municipalities that connect 
to it, the more data we have and the stronger the 
technology becomes. 
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c. The methodologies for making connections 
between systems and the policies to manage these 
will be useful in all municipalities. 


2. The proposed CHIRP is being developed with 
Alberta Health Services in partnership with AAHC 
as a prototype for bringing together meaningful 
health and population formation for a community. 
This is critical to make better use of the many data 
sources and indicators available in large health 
systems. The frameworks to create community-fo- 
cused information and the resulting dashboards will 
be available to other communities. 


3. The partners will share learning and key success 
factors learned through the large-scale community 
engagement process. 


Municipalities are responsible for providing a healthy 
environment for their residents to live, work and play, 
and our municipality's unique partnership with the 
AAHC allows us to deliver a truly collaborative focus 
on health that can be replicated in other communities 
across Canada. 
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Becoming Canadas healthiest community will require 
continuous learning, engagement, and improvement 
to the health initiatives in our community. If we do not 
measure, we will not progress and achieve health gains 
in our community. 


Our vision of becoming Canada’ healthiest commu- 
nity and achieving our Challenge Statement of adding 
3+ years of healthy life expectancy over 5 years, can 
only be accomplished through a series of collective 


WELL-BEING HEALTHY OUTCOMES 
MEASUREMENT MEASUREMENT 
AND REPORTING AND REPORTING 


Figure 2.1 shows engagement of individuals, health 
outcomes, well-being and improved resource use, supported 
by the determinants of health and open data and connected 

technology can increase health life expectancy. 
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efforts and projects. Our performance measurement 
will be achieved through two main components: 1. 
Community Health Engagement; and 2. Technology. 


To increase healthy life expectancy, we need the 
participation of individuals, and we need to measure 
well-being, health outcomes and improved resource 
use. Monitoring results each year will provide feedback 
regarding successes and citizens’ needs to deepen 
community engagement work for community health. 
The availability of open data and connected technolo- 
gies will be an important enabler to engage individuals 
and improved resource use. 


The development of the Measurement System will 

be a year one initiative through a multi-stakeholder 
committee led by Airdrie & Area Health Cooperative 
(AAHC). This will build on expertise from Blue Zones 
and Alberta Health Service to create a “minimum 
data set of indicators” to monitor depth and scope 

of engagement, status of individuals relative to their 
perceptions of well-being, key indicators—leading 
and lagging—for health outcomes, and key indictors 
of changes in health care use. The objective is to 
express these indicators in dashboards for use in the. 
community. 


The measurement of well-being will be administered 
through individual participation and will provide 
them with an opportunity to reflect on their 

journey for health. There are several parameters in 
this survey that link to social determinants of health 
(SDOH) (Table 2.1). 
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Table 2.1 provides an overview of the measurement Y process for each of the four measures. 


Outcome 
Indicator 


Engagement 


Well-Being 


Health Outcomes 


Resource Use 


Processed under the provisions of the Access to 


EDT Metrics — 


e Technology 
Development 


* Community 
Health Initiatives 


° Well- -being apps r 


z Pilot of well- -being 


“measurement tool 


Leading & lagging 
indicators of health 
defined 


Comparative data 
sources outside of 
Airdrie identified 


Baseline measures - 


: identified / defined - e. 


Key health care 
metrics defined — 


. do 
Development 


* Community 
Health Initiatives 


* Use of COS App 


* Well- -being apps- 
usage & dota 


. : Well- -being scores 


" * Service Gnd 


resource utilization. 
from COS Opp. 


. Leading agate, 
indicators of health 


* Comparative data 
beyond Airdrie 


° Trends i in service use. 


per SS. 


. * Key health c care 


metrics reports — 
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| Information . 
Source — 


* Technology Devel- 
opment stakeholder 
engagement process 


* Tracking system 
for community 
health engagement 


Service Inventory 
analytics 


Individual AA 
| Connected Apps 
Well- Being Tool 
cos App 


Alberta Health Services 


* Above, including 
provincial & national 
surveys of health 
behaviours 


*COS App (Dashboards, 


ES analytics 


T Alberta Health Services 


Gathering - 
Process . 


* Chapter 6: 
Engagement 


+ Documentation of 
activities, summaries 


* Ongoing; periodic 
reports, minimum 
of annual trends 


Annual survey ` 


fo Y, 


. Ongoing, - 


annual trend d analysis 


* CHIRP annual reports 


* Periodic 


: | * Ongoing, annual trend 


-analysis - 


. * CHIRP annual reports À 


The goal of increasing healthy life expectancy is an 
overall and long-term impact, that can be achieved 
after in-depth and multi-year community engagement 
and strengthening of SDOH. Blue Zones has expe- 
rience in developing a predictive model to estimate 
such an impact and they will be reguested to provide 
this assessment at the end of this five-year project. 
Involvement of Blue Zones as a strategic partner offers 
the Airdrie community the opportunity to strive to 
become a “Blue Zones Certified Community” and 
reguires: 


1. Personal: At least 2096 of citizens take the Blue 
Zones* Personal Pledge and complete one action. 


2. Schools: At least 2596 of public schools become a 
Blue Zones School”. 


3. Worksites: At least 5096 of the top 20 commu- 
nity-identified employers become a Blue Zones 


Worksite™. 


4. Restaurants: At least 25% of independently or 
locally owned restaurants become a Blue Zones 
Restaurant”. 


5. Grocery Stores: At least 2596 of grocery stores 
become a Blue Zones Grocery Store”. 


6. Community Policy: Completion of the Blue Zones* 
Community Policy Pledge. 


'These measures are an impact and indicator of prog- 


ress toward our vison of becoming Canadas healthiest - 


community. Although this is not directly replicable 
by other communities without a commitment to Blue 
Zones, Airdrie will share learnings from this process . 
to help other communities put together their health 
engagement process. 


Several community groups will be using information 
and outcomes. This will be made possible by 
HealthSmart Technology and the resulting dash- 
boards. Some of these groups are already established in 
Airdrie (Mental Health Task Force, Domestic Violence 
Coalition, etc.) while others will be identified through 
the stakeholder engagement process. 


The Council Collaborating 4 Health (CC4H), estab- 
lished January 2019, is the community oversight and 
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stewardship body with over 20 local champions and 
leaders that is guiding the collective impact strategy to 
guide overall integration and coordination and com- 
munity-wide learning from all initiatives in the plan 
for Community Health. This is included in AAHCS 
letter of support. This community body endorsed 

the proposed Smart Cities Challenge submission on 
February 20, 2019. 


This group will: 


e receive annual updates on overall progress—for 
information and to link to other community initia- 
tives, | 


e be responsible for monitoring key progress steps and 
annual measures of outcomes from the community 
engagement strategy, and 


*. be the community sponsor for action related to 
enhancing SDOH per information received from the 
Smart Service Inventory system. 


Table 2.2 outlines the measurement requirements, 
milestones and timelines over the five-year project and 
Table 2.3 provides the payment schedule. Table 2.4 
logic model links the activities from the measurement 
requirements, milestones and time lines table, to the 
ability to complete the SCC funded technology devel- 
opment and to have outcome measure linked to the 
SCC. More details are provided in Chapter 3: Project 
Management. 


Page 218 of 341 


Table 2.2 provides an overview of the measurement development process for each of the four measures. 


Measurement = 
Wee —— 


Technology | 


* Project Team 


Development & Assembled Development 
Implementation completed 


* Community 

Engagement re * Prototypes 

SSI available for 
community 
testing, response 
& evaluation 


* Technology Vendor 
Engaged 


* Technology Devel- 
opmentBeginswith 
Community input 


e Initial Technology 


Community Health | « gommünw | Full community 2 
Engagement by Y Cau 
RANG: | -Initiated - begins | 


|s CHIRP Devel- 

T -opment begins 

| including. develop- 

|. ment of well- eina 
| measure. | 


-of outcomes 
Community - 
BO | 


EET Measurement 
Plan defined 


| D < Baseline | mea- - EE n 
-sures of outcomes E m 


Table 2.3 piod: the proj ject ne schedule over Me i 
Project = . : : ; 
Payment © 
Schedule . 
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| Ts $3,579,513 11,643,034 | $1,575, 616 $1,591,838 [$1,609,999 | $10,000,000 


Table 2.4 provides the logic model for the project. 
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Maen dam a LES 
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p iw 


NEEDED , — p —MM MM ———i 
| Development of Smart Service - Development of Prototype, year 2, Development Project Milestones—per Engagement: - i 
| inventory (SSI) with modification thereafter i project plan - User trends | a iL Ade leaders 5 year 
: hid : assessment o 

imis BOR ies - Development of System Navigation | : | Social Determinants of Health Summary Well-being a. the value of the SSI to operationalize | 
| , g } integration nodes to the community | (what's in the community by the 8 : SDOH's 
| cross referencing to SDOH) y | 
| | 


- Dashboards planned and developed | modified AL es RYN eer a LE | 


i 
Engagement of Users re Prototype 


^ 


er RT : i DD UNI DD NEM a) ep ae ae] 
Development of Dashboards and - Well-Being measurement tool developed i, “—— rint is | 
| E  — . . — — I i 
! - through technology vendor working | : į- CHIRP created & populated with a a Engagement; | Value of CHIRP prototype fora major — | 
with hired staff (dashboards) health-relevant data ' t Development Project Milestones—per - Use of Dashboards i ' | health system like Alberta Health Services, | 
AAHC with partners in-kind — . ; | | | project plan — as well as value to community leaders 
development (CHIRP) i Linkage of additional health applications Po] | 
. | based on community needs and value | r | ] i 
nine. T rs EI DIS E DID FONHEDDIG | 
Community Health 
Engagement by AAHC 
—— —  ——Ó ——— HY E x ror ym 
Community engagement per “healthiest : i Annual report re: i Status of community to meet BlueZones 
Airdrie powered by Blue Zones oe Development Project Milestones—per E ; a. Engagement | : 4 Certification Criteria—after year 3 
Collaborative” i—— - Multi-year engagement plan P b. Well-being $ 
| project lan 
- supported by local P — 


| c. Health outcomes Projected Impact on life Expectancy 
implementation team : d. Improved Resource use j after year 5 
oe —— | rr — dl Mic 


| [p | E. 3 | 
Assess status of SDOH in the PC , i | ; | j 
] Community ~ CC4H to examine outputs rom t and : + i 
| - based on input from SSI | HealthSmart Technology & develop Work to Begin in year 2 & 3 of project Project report re changes made, cross- . 1 See above input to overall value of Sl as | 
-— 


mto 


| d : NS 
development & Ue improvement / integration plan ased on Tech development referenced to engagement trends vehicle to operationalize SDOH's 


i 
MM — 


ÉGARD à RE CR a e ea a n 


Table 2.5 outlines the risks and assumptions for the development of the HealthSmart Technology. 


Information Management Lifecycle: inadequate and/or outdated * Leverage our investment in technology. 
policies, practices and/or procedures that may hinder ability to l | | | 
provide high quality information assets that meet its strategic and | * Increase quantity, range, complexity and relevance of information. 


operational goals and objectives. a 
p g J * Increase the need for the maintenance of electronic information. 


* Increase electronic service delivery. 


* Increase expectations of the pubic and stakeholders. 


Inability to utilize analytical procedures, budgets and other | to * Enhance. functional activity management involving direct - 
information to- identify variances, unexpected results, or r unusual- - fnündgement n review of nf gorommdnice md activities. | 
trends for subsequent follow-up. - | |n no oe ee 


Gomplionce risk: lack of rien with jegislūtion and * Enhance functional activity management involving direct 

regulatory requirements may result in unacceptable performance | management review of performance and activities. 

and cause an inability to achieve financial, operational, and 

stakeholder objectives. * Development and implementation of organizational legislative 
compliance monitoring program. 
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The scope of the project includes the following: 


« A HealthSmart Community Operating System 
(COS) 


o The framework that allows data to be securely 
accessed by individuals, groups, organizations 
and the community. The COS provides a “virtual 
handshake’ allowing the transfer of data from one 
party to another. Only encrypted transactional 
data is stored, Aggregated unidentified data may 
reguire storage. No other data storage will occur. 


e The packaging and preparation of the HealthSmart 
Core COS to allow for implementation in a 
municipality / community environment. Airdrie 
will be providing a template for other communities 
in Canada. Other communities will be able to adopt 
and modify the Airdrie model to fit their needs. 


« HealthSmart COS Application Programming 
Interface Sree i 1ttps:// Www.yo outube.com/ 


Mi m ry 


We atc hi 4: eR I A A TY 


o The COS API will be the master API that other 
applications can use to connect to each other. 
The master API is the sole location providing the 
connection point for all applications. 


o Custom API development for other systems to 
connect to the COS. 


Smart Service Inventory (SSI) — a smart navigation 
system allowing users to know what services are 
available locally, how to access, why to access, and 
why it is best suited to them based on their own 
individual profiles. 


Web portal integration for user access. 
Mobile applications for user access. 


Governance on how the technology will be managed 
and sustained. 


Stakeholder consultation and community engage- 
ment for release timelines, accessibility and usability 
of the web portal and mobile applications. 


Stakeholder engagement and landscape analysis on 
SDOH for what service inventory is most important 


in order to prioritize versions of service inventory. 


Stakeholder engagement of businesses, not for 
profits, and public organizations. 


The City of Airdrie (CoA) follows a standard project © 
methodology in accordance with the Project Manage- 
ment Body of Knowledge (PMBOK?) with adaptations 


to align with public organizational practices for use of 


public funds, approvals and procurement legislation. 
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Table 3.1 provides an outline of the standard CoA Information Technology Project Life Cycle.. 


PM Phase _ 


Initiate 


| _ [To produce more detailed information, that willbe — 
o required by funding. t technical and business groups. - 


Implement | Thi 
= es solution c concept 


Processed under the provisions of the Access to 


| Pui rpose | 


To identify that: T ob or opportuni eae within ihe 


business; the solution may be non-trivial in nature; and, 
a Business Sponsor is willing to be accountable for the 
solution. 


This phase is used fo develop d description of what the 


project will deliver, who is involved and how and when if 
will be done 


E The. solution, ds aaa concept, will be designed, 
- devel oped. ; tested, and turned over to operations. Any. 
-| training requirements : will be delivered i in this phase. | 


During this phase Ane ni project pem liis and is delivered 


to the intended users. 


€ This. phose begins. after prts solution has been delivered. e 


qu Gate. Reviews & Approvals - 


At the Project Initiate Gate, the X m decisioni is 
reached: Is the project request endorsed and prioritized by 
the Program / Project Steering Committee. 


Project Resources are assigned. 


| At the Project Assess Gate, the following decision i is 
reached: Is there financial or business viability? Does the 
Program / Project Steering Committee approv m 


: Formal presentation to the Progra M / Project St Ste ring 
o Con mitte. K nee 


: OM the project implement gate, the following : decision - 
is reached: Has the scope been delivered and does the. : | 
implemented solution meet the needs of the business’ d 


| During go-live phase, the following decision is reached 


by IT leadership: Is the project team and operational staff 
prepared for the change? 


^ the | roject an Gate, the folowing decision i is. TEE 
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Table 3.2 provides a summary of the milestones for the project. 


Governance model 10! Ta JU deci Movemner 2019 E a DE le Governance Model : 


External Audit of "per Trendy siano Audi Audit mem to rpg Canada. 
September 2020 


Community Employee Benefits d . | Annually starting in Annual CEB Report to Infrastructure Canada = 
Reporting | | August 2020 - | 


Program Steering Committee approval of November 2019 
project scope 


Stakeholder Engagement & Communications | March 2020 What We Heard Report 
- Visioning & Ideas for COS 


Requirements approval — March 2020 | 


April 2020 Business Case 


Program Steering Committee approval of 
business case 


Post Request for Proposal 


.| May 2020 


Proposal Request for Vendors- 


Tentative award i | September 2020. Contract Negotiation | | | 


Execute contract as à October 2020 _ | Technology Vendor Contract Awarded 


COS Go Live July 2021 Foundational System is Live 


COS Dashboard VI = sf November 2021 | Dashboard V1 is Live 


COS Dashboard V2 - - |November2022 | Dashboard V2 is Live | 


COS Dashboard V3 November2023 | Dashboard V3 is Live - 


COS Dashboard V4 - November 2024, Dashboard V4 is Live - | Mon 


Not for Profits (NFP) functionality added to | December 2019 | NFP able to create accounts in CoA Business Directory 
City of Airdrie (CoA) Business Directory — + ges AR er pe 
Census API April 2021 Census API go live for COS 


| CoA ED TE API 90 live for cos 


Wearables API | | April 2021 - res golive forcOS —— 


Perfect Mind API icc ee] ADM 202) 3 


Processed under the provisions of the Access to Page 223 of 341 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


Milestone 


GIS Data API 


June 2021 |... 


| uu GIS Data API go live for COS - 


Social Media API ‘| July2021 Social Media API go live for COS mm 


Se TASER Pen Dato | January 2022 . -— Government Uae Data Platform API go live fort COS 
Platforms API posa 


Stakeholder Engagement & Commitificafions June 2020 | What We Heard pm : 
Service Inventory 


Service Inventory VI & API = | January 2021 | Service Inventory VI & API connected to COS x 


Service Inventory V2 & API — | October 2021 ~ | Service Inventory V2 & API connected to COS | 


Service oe & API — mE June 2022: — NE nd & API connected to cos 


Service RA VA & API March 2023 Service inventory VA & API connected to COS 


eMental Health API & Dashboard quad d pus "e MEE API & Dashboard built & connected to cos. 


Well-Being Tool API & Dashboard rae a 2021 API & Dashboard built & pieced to COS 


People Like Me API & Dashboard November 2021 | API & Dashboard built & connected to COS —.— 


Micro Credentialing (Employers & Volunteers) | January 2023 API & Dashboard built & connected to COS | | 
API & Dashboard 


Clinical Systems API & Dashboard |... ae 2023 .. .. | API & Dashboard built & connected to COS 


Accessibility & Usability Communications & February 2 2021 What We Heard Report | | | 
Stakeholder Engagement 


Web Interface for COS asi E x Tue. 2021 COS eonneered to sees le Portal 


Mobile is Aves V] for COS cpanel: October 2021 | Mobile er v ava labie to connect to 5 COS 


Mobile Apps V2 Tor COS nt sn October 2022 ` zu E Ji : ‘Mobile aaah v2 available to connect fo COS © 


Mobile Apps V3 for cos TU HN ‘october 2023 Mobile UN V3 svoilable to Ed to COS 


Mobile: TE V4 for COS eae Dr November 2024. ss PE Miu s available lo connect to Dt 


Communications & Stakeholder Engagement emen Community Evaluation Report - Em 
- Evaluations & Ongoing Sustainment | o7 pud e qu M ey 


Closeout Popor Ox DOD! to program | November 2024 | Closeout Report 
Steering Committee — | a ar P d T M 
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Table 3.3 provides the project plan based on approximate start date of September 2019 This date is dependent upon receipt of funding. 


Mth 1-6 Mth 7-12 Mth 13-18 Mth 19-24 Mth 25-30 Mth 31-36 Mth 37-42 Mth 42-48 Mth 48-53 Mth 54-60 


Web interface. Ponal Un gate 


Mobile (iOS/Anaroid) 
interface 


1410 days | Tue 19-09-03 | Wed 24-11-20 


Thu 24-10-10 - 


Annual External Audit of Funding Use 3 li5doys |Fr20-08-98 | Thu 24-10-10 


. | Annual Community Employment Benefit — | 110 hrs. 1065 days | Fri 20-08-28 


— | COS Governance nr 126 days |Fri20-09-11 


Determine COS governance scope - Fri 20-09-1 


5 days | 


| 8 


: TERR IST E o qoe = ao ar EE Er ae + ce 
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| Task Name — | JA 2 E Duration |S € E. Finish - 


1. i 3 Procurement for Foundation Gn 143 trac 39 days Fri 20- 09. 25 Wed 20-1 i 18 
Consultant 


e Prepare & & Gather Quotes c â _ te o cT LD zs a a Fri 20- 09- 29 | Fri 20- 10: 02 


11132 | evaluation of Guoles- IF 20-10-02 | Fri 20-10-09 


S Reference checks | 


Phase 1 Stakeholder er Engagement & 
| Communications 


pu Stage 3 evaluation - other Sert. | 168 hrs. 
corporate evaluation | | 


p Stage 4 evaluation - ee cheas. T56 e days | Thu 20-05- 14 Wed 20- 07- 29 
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o | Task Name | B n [p | Duration - [St | Finish - 


Stage 5 evaluation - edanionsirations: 1264 liis 22 days Ts 20- 07- 28 Tue 20- 08- 25 


SIS Stage 6 6 evaluation - pricing - | Tue 20-08- 29 ? Wed 20- 09- 02. 


"o PIA/PRA 30 poem T Wed 20-09-02 | Thu 20-10-15. 


aoe Financial Mn, for p uo SU eT 300 days ee Tue 1 19- 09- 03. : Fri 20- 10- 16. 


— Piece contrac E TFri 20-10-16 | Tue 20-10-20 


Eu Y p _ 24, 292 hrs: us 5 TSAS oe aS Mon 19- 12- 02 Wed 24- 11. 20. 


| 300 hrs. | P | Tue 20- 1020. | Fri 20-12-11 | 


m TT 922 hrs. [123 "m | Mon 20-12-14 | Wed 21-06-02 


dre T Tue 2] -06- 29. a Wed 21 -07- 07. 


4. 1. 13. | cos Dashboard Vi 1649 his. [102 rom | Wed 2 21 -07- 07 | Tue 21- T 28 


— o ep 150 hrs. o | | "Tr Wed 21-07- 07 | Tue 21-08-03 


c Go Live | 


4. 7 15 | cos Po & Dashbodrd V3 1568 TS 92 20 | Thu 23- .07- 20 Mon 23- 11 20 
4.1.15.1 eres  — hc — 20 days Thu 23-07-20 | Tue 23-08-15 


re a ONU po eee - a in c CB Tue 23- 08- 19: Tue 23- 10- 7. 


eee cos Upgrades & Dashboard v4 | 569 his. | 1" o 5 | 11 Thu 24- 07- 18. - Wed 24- 1120. 
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oe Task Name. 


| Not For Profit Organizations added? 10 a € | 


pe E Business Directory - 


| oe | : els Data APL 


ve Social Media API 101 hrs. 34 days Wed 21-06-16 | Mon 21-08-02 


>> Local, Provincial ss Federal nu Data c E 721 hrs. ; — r 126 n : 3 Mon 21- -08- 02 | Thu 22- 01 20. : 
= | Platforms API - E Dm pe $ : 


E Service eno" 18,320 hrs. 790 dms TThu 20-04-16 | Thu 23-03-23 


| Phase 2 Stakeholder Engagement ond | F 220 hrs. | a " a a 20- 04- 16: : Mon 20 06-08 
Re Communications - p zu PLEIN. E 
-— Service Inventory Vi & API 2 050 hrs. 200 rv | Wed 20- 04- 29 |Thu21 01-28 


vem Service one v2 & API | pum a 2, 050 hrs. - 200 Daas € T Thu 21- “01: 28. |" Wed 21- 10- 21. 
"T Service emm V3 & API 1750hs. 180 TuS Wed 21-10-27 | Mon 22-06-27 
Mr Service Nen Y? KAP goin 2, 050 hrs. | | 200 OUS | i Mon 22- 06- 27. : Thu 23- 03- 23. 
mn eMental Health COS APIs & Dashbodrd”. 375 bis: 150 days Thu 21 n] 28 | Thu 2] -04- 08. 
GUTES 2 Well- i Bead Tool COS APIs & Dashboard - ee 375 hrs. â C | _ | Tue 21-06- 29. | Fri 21- -09- 03. 
Bree Like Me (Curafio) C COS APIs & 375 iis. [50 days Fri 21 -09- 03 | Fri 21- 7 1- 1-12 
Dashboard 
o | Comnentinity d Involvement cos APIs & | : 35 hrs. c E - n Weg 22- Ti 23 : Mon 23- 01. 30. 
| Dashboard ES e E | 


_ Clinical Sens COS APIs & Dashboard 375 hrs. 50 TH | Mon 23-01-30 | Thu 23-04-06 


; D | poses ill and Le 
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^| Task Name 


to Create | project status ion 126 hrs. | 1394 do Fri 19-09-06 | Fri 24-11-01 
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e Technology and security subject matter expert 


GIS Analyst 


e Procurement services 
Steering committee members are representatives 


from the CoA and the Airdrie & Area Health 
Cooperative (AAHC) and provide program oversight e Risk, privacy and governance 
and governance. Members are existing staff of both the 
CoA and the AAHC. Possible members from AAHC: 
Chief Executive Officer, Chief Financial Officer, 
Chief Technology Officer; CoA: Chief Administrative 
"Officer or delegate Director of CAO Office, CFO / 
Director of Corporate Services, IT Manager. 


Corporate information governance leads 


* Communication and engagement 
subject matter expert 


Support resources reguired for specific tasks with 
limited time engagement. 


The Project Manager, two Developers, Business 
Analyst and Data Analyst will be new full-time 
positions and the Program Manager will be a new 


Finance subject matter expert 


Technology and security subject matter expert 


part-time position, all hired specifically to work on the Risk, privacy and governance 


project implementation. These positions are based on 
agile development and will be hired when their area of 
expertise is reguired for work to be completed. e Communication and engagement subject matter 
expert 


Health subject matter expert 


Support resources reguired for specific tasks with 
limited time engagement. Software Development costs are estimated at $4.5M 
based on guotes provided by vendors that build this 
type of technology. Chapter 8: Financial and the 

» IT Applications support financial plan in the appendices for details. 


e IT Developer 


Figure 3.1 shows the structure our Smart Cities Challenge initiative. 


Provide Oversight c 


Accountable for the prc 
* Team lead and accountable 


Project ma nager ov sees 
ihe projects within the pla 
for their scope, time, 


Project team member 
are accountable for completing 
tasks as assigned within 
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Project risk will be managed based on standard 
project risk management methodology. Project Risk 
Management outlines the principles of effective risk 
management: 


+ Plan Risk Management 

» Identify Risks 

« Perform Qualitative Risk Analysis 

e Perform Quantitative Risk Analysis 
. Plan Risk Responses 

* Implement Risk responses 

* Monitor and Control Risks 

(Source: PMBOK Sixth Edition) 


A risk register will be used to capture, manage and 
monitor risk details, including: 


e Cause and effect 
e Probability of risk occurring 
e Impact to project if occurs 


e Response strategies and actions 


Risk mitigation and response strategies will be deter- 
mined based on whether the risk is a threat (negative) 
or opportunity (positive). 


e Avoid 


o Avoid / eliminate risk by creating workarounds 
(e.g., changing the project schedule, adjusting the 
project objectives (scope), or taking other action 
to avoid the event). Protect the project from the 
impact of any risk. 


e Transfer 


o Transfer responsibility to manage the risk to a 
third party, with shared responsibility of ownership 
of the risk, usually for a fee. 


e Mitigate 
o Seeking options to reduce the probability and/or 
impact of the risk to an acceptable threshold (e.g., 


spend extra time or monies to reduce the risk on 
the project objectives). 


e Accept 


o Take no action until and unless the risk occurs and 
deal with the possibility of it occurring. 


Table 3.5 lists a of sample risk events that may occur and that the project team will identify, analyze, manage and monitor. 


Type ¢ of. Risk ; Examples . 


Technical, Quality. o or 

Performance Risks 

External Risks —— 
BLEU Soe ee RE ene ve o and weather. 


Reliance on unproven or ai mE aredi PPer odis pem term "9 mq 
process roadblocks, new emerging initiatives, increases in complexity, etc. 


‘Shifting regulatory environment, t, labor i issues, S changing e customer priorities, government agency. risks, a 


Ss : Consultant and vendor contrac risks, c contract hype and contractor responsibilities. 


Organizational Risks Lack of prioritization of projects, inadequacy or interruption of funding. néxaeiienced hu Lou 
developed and trained workforce, and resource conflicts with other projects in the organization. 


Project Management Risks © | Poor allocation of time and resources, inadequate quality of the project plan, lack of Td manager | 
MM yddo delegated authority, and lack of project management disciplines. YH o E 


Change Management Risks Poor user adoption, users s not c aware of existence, lack T eS of how to use he E or 
its functionality. 
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e Exploitation 


o Aiming to take advantage of a positive risk (e.g., 
PM and project team take advantage of a holiday 


weekend to work on the project uninterrupted). 
« Enhancement 


o Tries to make the conditions just right for a 
positive risk to happen. A tremendous amount of 
time can be saved and project costs if a milestone 
were to be finished by a given date, and to do 
so, extra resources need to be added to help the 
effort-driven work so that the team can complete 


the milestone by the specific date. 
e Sharing 


o This risk response allows the project team to 
partner or team with another entity (third party) 
to realize an opportunity together. 


* Accept 


o Willingness to take advantage of an opportunity if 


it arises but not actively pursuing it. 


All procurement opportunities for the project imple- 
mentation will follow the CoAs procurement policy, 
which establishes the general directions, philosophies, 
values for the procurement of goods and services, and 
addresses the legislative and liability restrictions the 
CoA works within. 


The CoA Procurement policy can be found on the 


` FN 


2 - [dy Pe aryar if yd ck 173 wabi 3 RYN DOD ayb 
H 5 af R7 TY SUR SEE En OT FEES fac id yddo 
O Wc site. (PLL LLAD f VV VY VA GG LEE SR Lady OO LA EE il. 
` $ pu. 


cimriiiog14d) 


The CoA is committed to the acquisition of goods and 
services at the best value while treating all vendors 
equitably through a procurement process that ensures 
integrity, transparency, accountability, efficiency and 


consistency. 
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The CoA acts under all applicable legislation 
including: 


e Alberta Municipal Government Act (MGA) 


e Agreement on Internal Trade (AIT) (referred to as the 
Canadian Free Trade Agreement as of July 1, 2017) 


* Comprehensive European Trade Agreement as of July 
1, 2017 


e New West Partnership Agreement (NWPTA) 
» Applicable competitive bidding laws 


a Freedom of Information and Protection of Privacy 
Act (FOIP) 


We will be developing an integrated stakeholder 
engagement and communications plan focused on 
involving stakeholders in the design, functionality and 
usability of the technology, understanding their needs 
and requirements and providing them with ongoing 
information about the project and how to get involved. 
The summary of this plan can be found in Chapter 6: 


Engagement. 


We will develop an integrated stakeholder engagement 
and communications plan focused on external stake- 
holders. More information can be found in Chapter 6: 


Engagement. 


We will develop a plan for internal project commu- 
nications to ensure the project team and partners are 
keep up-to-date about project activities, planning and 
implementing for engagement and communications 
activities and feedback collected to support the build 
and upgrades to the technology, and to ensure an 


ongoing understanding of roles and responsibilities. 


We will be using activities like recurring meetings, 
project updates, status reports, lessons learned, share 
folder access, project planning tools and information 


flow as part of our project management strategy. 
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Smart Health Information (SHI) is all about con- 
necting disparate data sets to generate new insights, 
which will inform health efforts by individuals, 
groups, organizations, and the overall community. The 
HealthSmart Community Operating System (COS) 
enables SHI and will inform actions. SHI will identify 
new connections and linkages in the community, 
strengthen and drive new and existing health initia- 
tives and foster innovation and change. Through our 
existing efforts in the community, we are creating a 
SHI roadmap towards better health and well-being for 
all. The COS will enable our efforts, breaking down 
silos and creating the capacity for existing platforms to 


communicate and share data securely and privately. 


The COS is a smart information exchange. We 

do not need to recreate existing platforms or data 
repositories, nor will we need to store data. The COS 
is a connector, allowing information to securely flow 
between existing systems. We will reform the data 
landscape away from data acquisition, collection, 
storage, and toward the concept of knowledge / 
insight sharing, enabling the following: 


e data mapping, sharing, and utilization 
e the ability to measure and monitor 


. providing customized content to inform improve- 
ment efforts 


» information flow in support of effective planning 
and decision making 


e system interoperability 


Figure 4.1 shows the COS and the Smart Service Inventory connecting to user dashboards, MyAirdrie (the City’s service platform), other systems 


and platforms, and the CHIRP. 


Smart Service Inventory 


P 


OPERATING: 


CHIRP 


(Community Health 
Information 
Resource Platform) 


MyAirdrie 
User Dashboards, 


Tools, Engagement 
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e engagement and community building 
« innovation 


Availability of data is not the issue. Data is all around 
us. The issue is bringing the right data together to - 
answer questions specific to a need. In parallel to 

the development of COS, the Airdrie & Area Health 
Cooperative (AAHC) will be developing a Commu- 
nity Health Information Resource Platform (CHIRP). 
CHIRP will be used to manage health and wellness 
specific tools and data sources. A connection between 
CHIRP and COS will allow for the answering of the 
health and wellness specific measurements as outlined 
in Chapter 2: Performance Measurement. The COS 
will also connect to other data sources, both 

open and those managed by the City 
of Airdrie (CoA). Information in 
each of these sources will be en- 
hanced by engagement in the 
community. COS creates 

an information engine 


allowing for continual 


improvement. 


A HealthSmart COS 
App will be an inter- 
face to individuals, | 
groups, organizations, 
businesses, and the 
community to informa- 
tion. Available through 
any platform, either on the 
web or as a native mobile app, 

the COS App will act as a “Way 
Finder for Health,’ providing insights 
through a smart service inventory and user 

managed dashboards. Gamification will be integrated 
throughout with an emphasis on fostering community 
engagement. Gartner Glossary defines gamification as 
“the use of game mechanics and experience design to 
digitally engage and motivate people to achieve their 
goals” Gamification will allow for healthy competition 
across the community, fostering behavioural change. 
Built-in translation services will allow for any language 
based on community needs. The App will be built 
using open source technologies and will be available 
freely to other communities to use and customize 

to their own needs and will consist of three main 
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components: The Smart Service Inventory; Health 
Dashboards; and Profile Manager. 


1. SMART SERVICE INVENTORY (SSI) 


We will build a smart digital community inventory of 
available programs and services related to health and 
health care that can be digitally accessed and used by all 
individuals, groups, and organizations in the commu- 
nity. This inventory will be a community connector and 
way finder helping users and organizations navigate 
their available options, collaborate for gap filling, avoid 
redundancies, and optimize time spent on health 
activities. It also lays the groundwork for stakeholders 
working together to eliminate duplication and collab- 
orate to identify and fill gaps in programs and 
services. 


We will engage local individuals, 
groups, and organizations and 
expand the existing CoA 
Business Directory to 
include all organizations 
and social services. We 
will utilize the data 
from this existing 
Directory to provide 
the foundational 
— informational elements 
(that can be produced 
by any other communi- 
ty). A project development 
team will be hired to 
build an interface and smart 
functionality (using open source 


technologies) that organizations can 
use to access, input, and collaborate. The SSI 
will allow for individuals, groups, and organizations 
to navigate to find resources, powered by artificial 
intelligence, pushing relevant information to users. 


Development of the SSI will be influenced by local 
groups including Council, Collaborating 4Health, 
Mental Health Task Force, and Domestic Violence 
Coalition. These and other groups have spent countless 
hours working in the community and understanding 
the community landscape. This group will help co-cre- 
ate an inventory of available programs and services 
available in the community that are well understood 
and can be well utilized by citizens. Groups will come 
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together with subjective organizational views — moving 
to create community ownership for a connected and 
informed community making decisions together 

and moving to a software that supports a shared 
information source. The SSI will become greater than 
the sum of its parts, allowing all users to contribute 
and collaborate. 


2. HEALTH DASHBOARDS 


Health dashboards will connect individuals, groups, 
and organizations directly to the data through a 

series of visualization tools. Content will be provided 
to users allowing them to both be informed and to 
compare themselves to others. The dashboards will 
be populated from data connected through the COS. 
Dashboard views will be customized to meet the needs 
of an individual, group, organization, or the overall 
community. Dynamic tools will be integrated to allow 
for viewing data in different formats, across time and 
for specific needs. 


Insights and gamification will be available, providing 
motivation for participation and involvement. We 
will work with local organizations to create a rewards 
system, further informing and connecting the com- 
munity. Surveys and user inputs will allow for a more 
customized experience. 


The Health dashboards will utilize a combination of 
business intelligence tools and custom created code. 
Metrics and reporting through the dashboards will 
allow for informed insights and decision making, once 
again acting as a way finder in the journey towards 
becoming Canadas healthiest community. 


3. USER PROFILE MANAGER 


Users will be provided with a profile administration 
tool within the COS App. Through the profile admin- 
istration, users will have the ability to: 


a. Manage account information — Each user will need 
to set-up their own account and login information. 
Basic demographic information will be captured 
to allow for secure authentication and capacity for 
connecting to the COS and associated data sources. 


b. Select connected services — The Profile Manager 
will inform the user as to what apps and services 
are currently compatible with the COS. Users will 
have the ability to select the services they would 
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Figure 4.2 shows four main components, Community, Core, 
API and Modules connecting to the COS. 


like to connect and integrate with. As services are 
connected, additional information will be available 
to the user providing a more robust dashboard and 
smarter navigation in the community inventory. 


c. Share information — Users will be able to create a 
network of peers and groups through the capacity 
to share information. Users will be able to select 
what they would like to share, whether it be specific 
data elements or a generalized dashboard. Sharing 
information will enable community development 
and accountability. 


d. View and manage information access — Users will 
have access to a comprehensive information audit 
log, allowing them to see how their data is used by 
themselves, connected services, and by shared indi- 
viduals and groups. Full transparency and control 
will allow each user to own their own information. 


. TECHNOLOGY DETAILS 


The COS will be a private blockchain, an algorithmic 
and distributed data structure for REDDF electronic 
Se anang D https://www.youtube. 
om/watch?vz3xGLc-zz: » built on open source 
chaps Based on our current sarc RE A 
ccs (https://www.voutube.com/watch?v-js3Zix 
c Deel twill s bes Suede as it ie prioritizes user 
privacy and security. According to IBM, “Channels, 
supported in Hyperledger Fabric allow for data to go to 
only the parties that need to know.’ The COS will have 
four main components: COS Core, COS Community, 
COS API (Application Programming Interface), and 
COS Modules. 
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HEALTHSMART COS CORE 


Built using open source blockchain, COS Core will 
establish an infrastructure and provide foundational 
components such as authentication, access, and securi- 
ty. User permissions and authentication will be vital to 
establishing a private and secure infrastructure to build 
upon. Unless an individual provides authorization to 
data, that data can only be seen by the individual. 


HEALTHSMART COS COMMUNITY 


COS Community is the customization of the core 

to meet the needs of the community. Customization 
will include administrative tools and configurations, 
algorithms, logic and capacity for system learning and 
evolution over time. We will establish a standardized | 
set of development protocols without the constraint 
of a single development language. COS Community 
will be compatible with a wide array of development 
languages (Python, NodeJS, Java, etc.) allowing for 
increased interoperability, innovation and shared 
expertise. We will work with a technology vendor 

to customize the blockchain to the needs of Airdrie, 
providing a proof of concept for other communities. 


HEALTHSMART COS API 
COS API (a master AU VE ied 


mSX Y) wil be aed enabling 
a ian et ae dis interchange and providing a 
central mapping and access point for data sharing. The 
COS API fosters interoperability through defining 
protocols and standards for system connectivity 

and information sharing. Third parties, innovative 
members of the community, and entrepreneurs can 


engage with and connect to this product / service. 

This will facilitate innovation and the potential of new 
businesses in the community and support the healthy 
community engagement initiatives to support a culture 
and shared vision of community engagement around 
health and the social determinants of health (SDOH). 


COS Community and COS API work together to form | 


a platform for individuals, groups, organizations, and 
the community to have access to, understand, and 
utilize information. 


HEALTHSMART COS MODULES 


Taking a modular approach will improve collaborative 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


efforts as development will not be confined to one 
vendor. COS Modules provide building blocks for 
shared development and innovation. We will be pro- 
viding the capacity for new and existing applications 
to connect with the COS. COS Modules will be based 
on best practices / industry standards, allowing for 
future friendly development and additions based on 
community needs and technology advancements. As 
COS is replicated in other communities, innovations 
and connected modules created in one community can 
be shared and utilized in another. 


APPROACH TO FUTURE-PROOFING 


We live in a world of apps, platforms, and devices. We 
are not trying to re-create the wheel. Interoperability 
is a core function of the COS. The concept of ^works 
with" has been used by Google, Amazon, Apple and 
many other of the leading technology companies. We 
will be implementing this concept at a community 
level. We will be taking a strategic approach when it 
comes to connecting apps and services. Apps, plat- 
forms, devices and other services will be vetted based 
on local community needs. 


We recognize that use cases and needs will evolve over 
the next five years. For every connection, we will be 
providing learning for other communities, including 

a connection “recipe book”, experiential learning, and 
policies. We will also be providing the code required to 
connect and integrate data into the COS App. We will 
work with subject matter experts and consultants to 
optimize implementation and user experiences. At the 
time of writing, we plan on focusing on the following 
use cases and connecting the following services 
(creation of APIs) as part of our smart community 
project: 


e Activity and Fitness Tracking. We will connect to 
devices like FitBit, Google Fit, and HealthKit. We 
will also connect to our local recreation system 
platform. 


e Health and Wellness Measurement. The (AAHC) 
has established partnerships with Alberta Blue 
Cross, Alberta Health Services, and Blue Zones. 
Through these partnerships, a health and wellness 
measurement tool will be developed that will allow 
for individual and organizational health scores and 


tracking metrics. This tool will provide the capacity 
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to measure and track healthy life expectancy (Chap- 
ter 2: Performance Measurement). 


Community Connections. Users can connect with 
others that are like them and share insights, access 
resources, and come together for a shared and 
connected health journey. 


Community involvement and Micro-credentialing. 
Provides the capacity of micro-credentialing and 
involving individuals and organizations through 
connecting opportunities for volunteering and 
employment. 


eMental Health. The local Mental Health Task Force 
has identified youth mental health apps as a 


strategy for change in our community. 
We will be working with this Task 
Force to integrate selected 


apps. 
The SDOH will be driving 


factors as applications are $ 
selected to be connect- f' 

ed into HealthSmart ~ 

Technology. We will 

create a partnership 

ecosystem where | 
everyone can work ( à 
together towards the | 


shared vision of becom- 

ing Canadas healthiest ^ A 
community. Our operating er | 
structure will allow for zm] 
co-development and focusing on 

meeting our community needs rather 


than on any one specific product. 


SECURITY AND PRIVACY 


Security and privacy will be central to the COS. We 
will develop a System Security Plan (SSP) that will 


comply with best practices identified through con- 
sultations with leading security experts. We will work 
with partners to conduct regular internal and external 
audits monitoring system security, risk, and privacy. 
The SSP will clearly delineate roles and responsibilities 
and will have tight control and monitoring systems. 
We will also be working closely with privacy experts 
and organizations. A risk framework and standardized 
approach will be interwoven in every stage of the 
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project. We will be in full compliance to local, provin- 
cial, and federal privacy laws. 


The design of the COS is underpinned by data and 
privacy considerations. COS will utilize leading edge 
principles and standards to authenticate and create 
identity maps for each participant. Keycloak, an open 
source identity and access management solution, will 
be integrated into the COS, providing capacity to have 
a secure single sign-on (one master login for multiple 
platforms) and enabling interoperability between 
existing systems without the need to store user cre- 
dentials while keeping information secure. Keycloak is 
built on standard security protocols, providing support 
for OpenID Connect, OAuth 2.0, and 
SAML. Users will be able to manage 
their own accounts, including 


b. «ur m á the ability to view history of 


use and connected systems 
that have been authorized 
for the single sign-on. 
Regular system 
utilization audits will 
be facilitated through 


w fll Hee A. an automated system 


access and usage log. 
Predefined rules will be 
built-in to automatically 
flag data breaches and/or 


— inappropriate access, and 
the appropriate parties (indi- 


vidual, organization, authority, 
etc.) will be notified. We will follow 
the rules identified by FOIP, PIPEDA, HIA, 
and GDPR. AAHC will work with Alberta Health 
Services and Alberta Health to define consistent audit 
standards and reguirements. 


The COS will allow for the sharing of data (e.g., 
insights, benchmarking, data transfer, etc.) as directed 
by the data owner or by predefined applicable and 
permissible use cases (e.g., medical emergency, 
preauthorized access) within the confines of the local, 
municipal, provincial, and federal privacy guidelines. 
Users will be able to select what information they want 
to have access to and will be in control of who else can 
access that data. 
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D 


Figure 4.3 shows a search query connecting a user fo various health related information. 


Curriculum will be developed locally, based on the 
technologies used in the COS, that will empower 
anyone to participate. We will use best practices to 
guide standards and processes and take advantage of 
existing curriculum platforms providing free coding 
training and tutorials. We will host hackathons and 
connect those with ideas to those with technical 
expertise to bring new innovations to life. Exposure to 
the community through healthy community engage- 
ment efforts will be further strengthened providing 


fuel for economic growth and development in Airdrie. 


Our movement is community driven, our technology 
will support and even further strengthen the ability of 
the community to get involved. Information enables 
impact and we see this as a vital component of our 
community transformation. 


The COS will require a collection of efforts from 
partners and experts. It will require community 
engagement and collaboration. Interoperability 

will be fostered as the COS will be both vendor and 
development language agnostic. Anyone will have the 
potential to contribute. We will partner with experts 
and industry leaders to ensure best practice. 
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DATA MANAGEMENT 


No individual or identifiable data will be stored in 

the COS. Data stored by the COS will be for the use 

of verification, security, mapping, and utilization 

of data including algorithms, data maps, and other 
configuration details. Some aggregated, non-iden- 
tifiable data may also be stored to allow for baseline 
analytics and comparative benchmarking. A series of 
information mapping and supporting databases will 
contain information such as the transactional ledger, 
containing mapping and configuration details for each 
participant and allowing for every system interaction 
to be securely verified and logged. All ledger infor- 
mation will be encrypted and will allow individuals : 
to have full transparency as to who, how and where 
their information is being used. All information will be 
stored on a Canadian-based servers. 


Partnerships will be developed with data custodians 
and managers to utilize APIs and other connectivity 
tools to establish interoperability of existing platforms 
and tools. The COS will have the capacity to execute 
search queries to retrieve relevant information from 
the appropriate sources as existing platforms are 
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connected to the COS. Information from the queries 
will be surfaced and cached temporarily through the 
encrypted COS App. Authentication through the App 
will be required in order to display usable information, 
providing security against hackers or breaches of the 
data channels. Where possible, metadata and knowl- 
edge about the data (content) will be surfaced instead 
of the actual raw data. 


A primary concern of any data centric engagement is 
data security. We will be leveraging zero-knowledge 
proof principles to create a trustless (a system that 
operates in the same manner regardless of the user's 
intentions honorable or malicious) and secure data 
management system that maximizes data integrity and 
truly allows individuals to own their own information. 
In addition to local, provincial, and federal privacy 
laws (e.g., Health Information Act, Personal Information 
Protection and Electronic Documents Act, Freedom 

of Information and Protection of Privacy Act, Digital 
Privacy Act, etc.) we will also be adhering to the 
General Data Protection Regulation (as a new set of 
rules, established by the European Commission, 
designed to empower citizens, to govern the privacy 
and security of personal data) to ensure that individual 
privacy is of foremost importance. No sensitive indi- 
vidual or entity data will be stored within the COS. 


DATA/ INFORMATION SOURCES 


We have identified four categories of information 
sources: 


1. Municipal Information Assets. The CoA has access 
to several data sources, including the Census, Rec- 
reation Centre, and Business Directory. These data 
sources will be essential in establishing community 
denominators as well as locally specific context. 


2. The CHIRP platform. Owned and managed by 
AAHC is used to manage health and wellness 
specific tools and data sources. 


3. Open Data Sources. Open data sources will be 
connected and utilized based on use cases and 
community needs. Managed externally, sources 
such as StatsCan or Alberta Open Data will be vital 
to provide comparative data and benchmarking. 


4. Other Data Sources and Platforms. Community 
organizations, external partners, and others may 
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have access to other data sources that are not 
managed by the CoA or AAHC. Connections 
will be made based on use cases and community 
needs. An example of another data platform will 
be our local food bank, and their use of the Link- 
2Feed platform. We will create connections and 
linkages to this platform to meet a specific need 
or requirement. 


The management of tools, applications, and data 
hosting is the responsibility of our partnering 
organizations. 


ACCESSIBILITY AND USABILITY 


Accessibility and usability of the COS App will be core 
to our technology efforts. Our development team will 
be working with design consultants that have expertise 
in gender-based analyses and accessibility. We will 
make the App cross-platform to allow for ready 
availability on any device. We envision three main 
access points for the COS App: 


The MyAirdrie Portal is currently used by the CoA to 
provide citizens with information about their homes, 
taxes, licensing, and several other services. Currently, 
over 22,000 households have registered accounts 
through the Portal. We want to provide a single con- 
nection point to facilitate access. The HealthSmart web 
application will be accessed through the MyAirdrie 
Portal. A single authentication between the MyAirdrie 
sign in and the COS login will allow for users to log in 
once to view all their information in one location. In 
addition to existing services on the MyAirdrie Portal, 
users will have access to new tabs containing the 
different components of the HealthSmart App. These 
will be embedded into the MyAirdrie Portal using 
encrypted web technologies and appear to the user as a 
seamless integrated experience. 


Native mobile apps (iOS / Android) will be developed, 
allowing users to have all their information securely 
available at their fingertips. The apps will be made 
available for free and work asynchronously with the 
web app. 
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developed to ensure access to personal information is 


Mobile Kiosks will be strategically placed in public available only with the proper authentication. Other 


locations (library, recreation centre, City Hall, etc.). 


smart communities have instituted smart cards to 


These kiosks will be preloaded with the HealthSmart authenticate users. We envision something similar for 


App, allowing for secure access and utilization by 


the public kiosks and data stations. 


anyone in the community. Protocols and rules will be 


Table 4.1 identifies the components of an effective technology risk management evaluation. 


Strategic 


Business continuity — 


First, we need to evaluate whether we want to be at the leading edge of adoption or wait to adopt until the 


technology matures. Second, given the peer-to-peer nature of the fechnology, it’s important to determine the 
right network and who fo partner with as our business strategy may be impacted by the different organiza- 
tional cultures participating on the chain. 


Third, the choice of the underlying platform may pose limitations in the services or products that can be 
delivered via the platform. 


Blockchain technologies i are generally resilient due to the redundancy resulting from the distributed pe 


— | of the technology. However, the processes built on blockchains may be vulnerable to technology and | 
. | operational failures as well as privacy breaches due to pes We need to have a Tobust business 
_ | continuity plan and governance framework to mitigate such risks. dul de "e 


Reputational 
Regulatory risk 


Operational and IT — 


Contractual | 


Supplier — . 


Unlike other IT type applications, blockchain technology is part ofc core a inrasitueture sand will have to work 
seamlessly with legacy infrastructure and legacy data platforms. Failure to do so may result in poor client 
experience and regulatory issues. 


Across the globe there's uncertainty around the regulatory requirements related to blockchain applications. 
Additionally, there may be regulatory risks associated with each use case, the type of users in the network, 
and whether the framework allows domestic or cross-border transactions. This may also include business 
cross-border regulations related to privacy and data protection. 


Existing. policies and procedures. will need to be updated to reflect new. business processes. Additional | 
< | technology concerns may include eed scalability and interface with h legacy systems in | implementing the £ 
. | technology. - | eu 


There will likely be several F Tevel a GLAS) b betwee naricpating nodes ad the "enun 
tor of the network, in addition to SLAs with service providers that will need to be monitored for compliance. 


e Firms may be rs to significant T third- d pary n risks since most of the s technology might be sourced from 
- | external vendors. - : 
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Consensus protocol 


Key management 


The transfer of value in a blockchain framework occurs using a cryptographic protocol that arrives at a 
consensus among participant nodes to update the blockchain ledger. There are several such cryptographic 
protocols that are used to achieve consensus among participant nodes for updating the blockchain ledger. 
Each such protocol will have to be evaluated in the context of the framework, the use case, and network 
participant requirements. 


-| While the consensus protocol immutably : seals a blockchain. ledger and no corruption of past transactions. is. 
a possible, it ìs still susceptible to private keys: theft and the takeover of assets associated with public ee 


5 p es. Digital assets may become irretrievable i in the case of accidental. loss or private key theft, especially 


Data confidentiality 


Dispute Resolution 


zs given the lack. of a single controller or a potential escalation point within the framework. 


The consensus protocol requires that all users in the framework can view transactions MEE to the 
ledger. While the transactions in a permissioned network can stored in a hashed format fo not reveal the 
contents, certain metadata will always be available to network participants. Monitoring the metadata can 
reveal information on the type of activity and the volume associated with the activity of any public address 
on the blockchain framework to any participant node. 


The current school of. thought for blockchain risk has warned of that the adoption of. distributed ledger - 
cu technology may introduce new liquidity risks. In current business models, intermediaries typically take on. 


c the counterparty risks and help resolve disputes. Dispute resolution i ina distributed trust environment i is a 


Business and 
regulatory 


Contract enforcement. 


requirement that will rely on predicted arrangements. 


Smart Contracts should accurately represent business, economic, and legal arrangements defined between 
parties in the framework. The smart contracts that are defined on a blockchain network will apply in a 
consistent manner to all users across the network. Therefore, these smart contracts will have to be capable 
of exception handling, and the consequences of these exceptions in the form of a programmatic output on 
the blockchain framework will have to be tested across the universe of all other smart contracts within the 
network for adherence to business and legal arrangements and compliance with regulations. 


Currently there is no legal precedent around. the enforcement of a smart contract in lieu of a physical © 


— | contract and. there are no regulations governing smart contracts. The data on a blockchain framework i is 


sus immutable, care should be taken to amend smart contracts to avoid. breaches. of existing regulation by | 
o; acting on data from the poste on the blockchain that c are not within the > omo legal l limits for a financial 


Legal liability 


Information security — 


p arrangement. - 


In a SONIS ORE network, the qnem liability remains unclear for an improper, erroneous, or a malicious 
administration of a smart contract resulting in a transaction with two or more entities on the network, 
causing assets to leave the network via those transacting entities. 


Smart contracts may be susceptible to security breaches and improper administration. Participant entities 
| or the network administrator will need a strong governance and change control process to deploy new 


or amend existing smart contracts. They will also need a robust incident management process to identify - 
| dnd respond to glitches i in smart contract operations. Oracles are entities that exist outside the blockchain - 
| framework but feed data to the network, they may. trigger 1 the execution of the smart contracts within the - 
= | network. The biggest risk to a blockchain framework may lie within. these oracles as these may be subject. 
| to malicious attacks to corrupt | the data 9 being a to o the blockchain. This may cause d I d domino | 
… | effect across the entire network. - | s WEILE 
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Governance is the process of identifying expectations, 
structure, and rules for participation. It is identifying 
the right stakeholders who will work together to plan, 
implement, monitor, and evaluate the project and 
initiatives. There are two governance frameworks that 
will comprise the governance plan for our project 
under the Smart Cities Challenge (SCC) initiative. The 
first will set the expectations, structure and rules for 
participation for the project implementation; and the 
second, for the ongoing operation and sustainability 
for the HealthSmart Technology. 


The City of Airdrie (CoA) is formed under the 
Municipal Government Act of Alberta, providing 
municipalities with broad powers. A Municipal 
Council can provide services, facilities and other 
things that are necessary or desirable for all or a part of 
the municipality. Health falls into this category. 


Through this enabling legislation, Airdrie City Council 
has committed to several health initiatives with a view 

to making Airdrie “Canadas healthiest community.’ To 
this end, City Council has supported several initiatives: 


e City Council directed staff to enter into a grant 
agreement between the CoA and the Airdrie & Area 
Health Cooperative (AAHC). 


o In 2016, City Council provided a $400,000 grant to 
the AAHC for health initiatives. 


e In February 2018, City Council supported the 
submission of an application to the SCC in partner- 
ship with the AAHC, based on Airdrie becoming the 
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healthiest community in Canada. 


e In August 2018, City Council directed staff to work 
with the AAHC to explore the role the CoA may 
play in furthering the initiatives of the AAHC. 


« In November 2018, City Council endorsed partner- 
ing with the AAHC on the initiative to make Airdrie 
a Blue Zones community. 


e In January 2019, City Council proclaimed 2019 as 
the Year of Healthy Living in Airdrie, that will be 
supported by a municipal communications plan. 


The CoA has partnered with the AAHC. 


The AAHC was incorporated under the Cooperatives 
Act in 2016 with the following mandate: 


To protect, promote and restore the physical and 
mental well-being of the members and to facilitate 
reasonable access to health services without financial 
or other barriers by broadly addressing the SDOH 
(social, economic, physical, health and health care 
environments and a persons individual characteristics 
and behaviours) specific to the members and their 
community (city of Airdrie and surrounding areas). 


The Cooperative aims at providing a proactive, 
participative, interdisciplinary and integrated approach 
to health and health care by involving members, local 
government, local businesses, local employers, local 
institutions and not-for-profit organizations to ulti- 
mately improve the quality and delivery of health care 
services through the Cooperative and other entities 
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organized for that purpose including entities in which 
the Cooperative holds an interest. 


Further, the Cooperative must at all times act in a 
manner that is consistent with the principles set forth 
in the Canada Health Act including the principles of 
accessibility and universality which promote egual 


access to all residents to publicly insured and publicly 
funded services. 


Each organization brings a unigue set of skills, 
expertise and Knowledge to the table. As the CoA is 
not currently in the health or health care business, the 
expertise and leadership of the AAHC in this grass 
roots initiative is invaluable. Both the CoA and the 
AAHC are committed and ready to implement the 
COS as an integral piece in achieving our Challenge 
Statement of increasing healthy life expectancy by 3+ 
years in 5 years. 


The CoA and the AAHC will enter into a formalized 
partnership agreement to ensure the completion 

and success of the SCC initiative. Although work has 
begun on a formalized partnership agreement, it will 
not be completed until such time as the SCC winners 
have been announced. 


As outlined in Chapter 3: Project Management, the 


Table 5.1 identifies the risks with the partnership governance model. 


governance structure for the implementation will 
follow a typical project methodology. There will be 

an Executive Sponsor from each organization - the 
Chief Administrative Officer for the CoA and the 
Chief Executive Officer for the AAHC. The Executive 
Sponsors sit on the SCC Steering Committee and are 
responsible for ensuring our program is in alignment 
with the SCC and the shared goals and expectations of 
the two parties. These shared goals and expectations 
will be outlined within the partnership agreement. 


Overall program oversight and governance will be 
provided by the Steering Committee. The Steering 
Committee will be ultimately responsible for the 
success of the program. Steering Committee members 
will not be compensated for their time or work on the 
program. 


Both parties will have equal say at the Steering 
Committee table, with each party selecting three 
members. The Steering Committee will operate 
under a collaborative decision-making model. In the 
event a collaborative decision cannot be attained, the 
Executive Sponsors will decide jointly. There will be 
an escalating alternative dispute resolution process 
included within the partnership agreement. 


As the grant recipient, the CoA will assume fiscal 
responsibility for the program. A paid Program 
Manager will report directly to the Executive Sponsors 


Conflicting goals between Discussions, meetings and partnership agreement revisions will occur to ensure the shared goals, 


the parties eee 
ps green 


Conflicting direction to 
program team members 


understanding and expectations between the pe are RN documented within the partnership 


Terms of reference for the Steering Committee will be prepared and clearly articulate the decision-mak- 
ing process and decision flow (Steering Committee to Program Manager to Project Manager to 


implementation team). The terms of reference will clearly articulate how program team members are to 
manage events that occur outside the agreed-upon flow. 


Political interference 


The CoA has formalized Council-Administration Information Protocols that une how program. team 


mempels are fo Tune ee direction from P Council. 


Conflicting priorities 


For the most part, conflicting priorities will not occur with the program team members as they will 


be hired specifically for the SCC project. Internal resources in both organizations, however, may 
experience conflicting priorities and capacity issues. It will be the role of the Executive Sponsor in each 
organization to ensure specialized internal resources can be accessed. 
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and be accountable for the overall program success. 
The Program Manager chairs the Steering Committee 
and establishes and maintains the program strategy 
and roadmap. This person aligns the program strategy 
with the shared goals and expectations established 

by the Executive Sponsors. The Program Manager 
provides regular status updates and escalates program 
risks, issues or decisions to the Steering Committee. 
The Program Manager will be responsible for the 
human resources required for the program and 
identifies, tracks and manages key metrics. 


A paid Project Manager will report directly to the 
Program Manager and be accountable for the projects 
and work outlined within the project plan. The Project 
Manager will be accountable for project scope, identi- 
fying and mitigating risks, timelines / project schedule 
and budget. The Project Manager will lead a team of 
developers, business / data analysts and vendors in 


their technical work. 


Various support resources and subject matter experts 
will be drawn from within the CoA and AAHC 

as required. These resources / experts will include 
technology, procurement, information governance, 
privacy, security, risk, finance, health, communications 
and engagement and will be compensated on an 
hourly basis. 


As outlined in both Chapter 3: Project Management 
and Chapter 4: Technology, the governance model for 


the community operating system is currently under 
review. Typically, successful open source platforms are 
governed under a foundation model. Early research 
has indicated foundations can be quite costly to estab- 
lish. For this reason, funds have been set aside early 

in the project plan to research and determine the best 
governance model for the COS. The global collabora- 
tion of Hyperledger, hosted by the Linux Foundation, 
is one of the options that will be considered. 


As outlined in Chapter 4: Technology, the COS will 
not house any personal or identifiable information and 
has been designed in such a way that the municipality 
will control access. Residents will access the COS 
through the MyAirdrie Portal. A single authentication 
will allow users to log in once and view their informa- 
tion in one location. This ensures that the municipality 
retains control over sensitive and personal login data, 
which is then subject to the Freedom of Information 
and Protection of Privacy Act of Alberta. For other 
municipalities in Canada, access will be controlled by 
the municipality and be governed by that municipali- 
ty's privacy legislation. 


The CoA has received letters of support from Premier 
of Alberta, the Minister of Alberta Economic Devel- 
opment and Trade and from the Minister of Health. 
These letters recognize the benefits that Airdries 
proposal will provide to its community and communi- 
ties across Alberta and Canada. 


A letter of support is included from AAHC and from 
Alberta Blue Cross. All letters may be found in the 
appendices. 


Table 5.2 identifies risks in terms of governance of the COS. 


Determination of detailed technology Incorporate into the project plan time and resources to explore the most appropriate - 
governance model for the community operating system. The project team has identified 


the need for aE DDR in this area and strong odis advice. 


governance and sustainability beyond 
project implementation. | 
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The City of Airdrie (CoA) and the Airdrie & Area 
Health Cooperative (AAHC) have conducted various 
surveys and hosted stakeholder engagement sessions 
to gather feedback from Airdrie residents on health. 
This information has been used to develop the stake- 
holder engagement and communications approach. 


For the past four years, respondents to the CoAs 


annual satisfaction surveys have consistently identified 


e Access to their personal health related information. 


e. Need for health-related information and access 
to services and resources through digital, online 
technology. 


e Sharing of information, they choose to share, 
between health providers. 


e Ability to manage and track their health through 
technology. 


This information was used to shape our initial 
proposal and our finalist proposal for the Smart Cities 
Challenge. 


health as one of the most important issues for Airdrie 


residents. 


The AAHC sponsored a stakeholder engagement 
process from Fall 2016 to Winter 2018, engage 
residents on health and health care. This included 


face-to-face sessions with hundreds of individual and 
organizations and two community events — one for 

the top 80 community leaders and one for health and 
health care leaders. These sessions informed a report 


to the co 


‘ 


$ Da ge 7331153 
FILLES Pii 


PI 


Participants in the stakeholder engagement processes 


identified several themes, including the following 
related to the HealthSmart Airdrie project: 
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As a follow up to the report, a four-day stakeholder 
engagement session was held in May 2018 to examine 
the potential of developing a partnership with Blue 
Zones. Over 600 individuals participated and provided 
support for moving forward with Blue Zones. Plans 
were formalized with Blue Zones in February for 
implementation of “Healthiest Airdrie, powered by a 
Blue Zones Collaborative” 


The CoA and AAHC developed and implemented a 
communications and stakeholder engagement plan to 
build awareness of the Smart Cities Challenge proposal 
based on our eight selected social determinants of 
health (SDOH), and HealthSmart Airdrie. This 
included the announcement of being selected as a 
finalist in the Smart Cities Challenge, stakeholder 
engagement at Airdrie Fest, the development of the 
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HealthSmart Airdrie website, an open house on 

' December 6, ongoing promotion of HealthSmart 
Airdrie RU A social media and radio, the Fr 
health blog : ': vww.mayorhealthblog 
challenges lied) to the SD OH nd a citizen survey. 


What we heard from citizens during this stakeholder 
engagement is that they are excited about the 
HealthSmart Airdrie initiative and how it can help 
support their health. Of the over 104 people that 
answered the survey, most respondents mentioned 
mental, physical and spiritual when asked about 


wellness. When we dug down into the SDOH, friends, 


family, community, food and our surroundings were 
the top three most important. 


Community 


Social Network 


Figure 6.1 shows community, social network, habitat and inner self 
connecting in the Blue Zones program. 


This limited stakeholder engagement has as told 

us that we need to continue to focus on building 
awareness about HealthSmart Airdrie and what we 
are trying to achieve, and not move to asking them 

to take action too quickly (see Table 6.1 Five Stages of 
Communications). This includes providing residents 
with information about the timing and phases for the 
project, sustaining communications throughout and 
providing opportunities for residents to get involved 
that are simple and easy. 


APPROACH TO STAKEHOLDER 
ENGAGEMENT AND COMMUNICATIONS 


CoA and the AAHC know that decisions are improved 


through stakeholder engagement of citizens and 
stakeholder groups and is committed to involving the 


public on issues that affect our community. We believe 


public participation will build stronger relationships 
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with our residents, increase public knowledge, increase 
transparency, and ultimately lead to better decisions. 
We will develop an integrated stakeholder engagement 
and communications strategy and plan that ensures 
citizens are informed, consulted and involved through- 
out the entire development process. 


Our stakeholder engagement related to health with 
include two processes: 1. HealthSmart Airdrie 
stakeholder engagement led by the CoA; and 2. The 
Community Health Engagement using Blue Zones 
methodology led by AAHC. These two processes will 
be coordinated, and stakeholder engagement activities 
leveraged where possible, and information shared 
between both projects. 


A brief summary of the Community Health Engage- 
ment is provided below to provide additional context, 
with the details for the HealthSmart Airdrie stakehold- 
er engagement and communications following this 
information. 


The purpose of the Community Health Engagement 
Project is to lead and ignite a community-by-commu- 
nity well-being transformation, where people live and 
work together for a better life. 


The approach used by Blue Zones Project is unique 
because it takes a systematic environmental approach 
to improving well-being through policy, building 
design, social networks and the built environment. By 
optimizing our environment - those settings where 
we live, work, and play, which influence our behaviour 
- we can make the healthy choice the easy choice so 
that we naturally adopt healthy behaviours. (Source: 
Becoming a Blue Zones Community Handout — Blue 
Zones Project). We will be the first city in Canada to 
adopt Blue Zones and will be developing a "Canadian 
version’ of the project. We will be hiring a local team 
of five and will receive world class training from the 
Blue Zones Project team to create local capacity and 
sustainability. 


HEALTHSMART AIRDRIE 
STAKEHOLDER ENGAGEMENT 


The CoA follows best practices as outlined by the In- 
ternational Association of Public Participation (IAP2), 
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including the use of the Public Participation Spectrum 
and Code of Ethics in its Public Participation Policy. 
Specifically, for the COS, access and usability, residents 
and stakeholders will be engaged at the Involve level of 
the Spectrum (Figure 6.2). We will identify and work 
with residents and stakeholder groups to identify their 
ideas and concerns and will work to incorporate them 
or address these in the development of the technology. 


Our approach to stakeholder engagement will be 
iterative, where input will be sought through each 
phase of implementation. We will work with internal 
and external stakeholders in both the design and 
evaluation of the technology, ensuring each version of 
the technology is inclusive of citizen feedback, address- 
es their concerns, and meets citizens’ expressed needs. 


Our stakeholder engagement and communications 
will be based on the following core principles: 


e a strategy and plan focused on the audience and 


stakeholders first and foremost and that connects to 


their values and what matters to them. 


an inclusive process that aims to identify and include 


all stakeholders to understand diversity of people 
and perspectives and needs, and seeks to understand 
different cultural values around the SDOH. 


«. transparent, plain language and two-way commu- 
nications and stakeholder engagement that educates 
and creates awareness about the technology, gathers 
feedback, demonstrates how input was used, and 
provides rationale for why any input was not used. 


an accessible format where stakeholder engagement 


activities can be easily accessed by everyone in the 
community. This means physical accessibility (such 
as providing online, in-person and in-situ activities) 


Table 6.1 provides and overview of the five stages of communications and how they relate to HealfhSmart Airdrie. 


Audience 


Communications 


Strategies 


Processed under the provisions of the Access to 


-| The audience may be 
| unaware or aware but 


not interested. — . 


* Build awareness 
through communi- 
cations channels 
that appeal to them 
and their interests. 


* Meet them 
where they are af 
(knowledge wise) 
and where they are 
having conversa- 
tions (location). 


* Ask them questions 
about health, 
provide them with 
the information 
they are interested 
in and begin fo 
discuss the benefits 
of healthy living... 


* Engage influencers 
and community 
champions. 


The audience may be 
aware of how to be 
healthier but have not 


| taken action to live 


healthier. 


* Provide them with 
information about 
health and the 
benefits of healthy 
living. 


* Provide them with 
easy access to 
information, tools 
and resources to 
help them to further 
understand how to 
become healthier. 


* Focus on issues 
people care about 
and how they can 
think about if in 
their daily lives. 


* Leverage events. 


Information Act /Révisé en vertu de la Loi sur l'accés 
a l'information 


The audience has 
decided they need to - 
do something but has 
'not taken action yet. 


* Show them the 
benefits of the 
action now (extra 
three years 
of healthy living) 
and how edsy if is 
for them to take. 


* Show them how 
to use the tools 
and resources 
and how easy 
it is to live a 
healthier life. 


* Provide them with 
personalized ways 
to become healthier. 


* Provide them 
with training 
and learning 
opportunities using 
the technology. 
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The audience takes 


action and needs > 
reinforcement. =- | 


* Show them the 
benefits of their 
action and how 
they can track 
their journey. 


* Help them 
to develop 
connections with 
other residents 
to build support 
networks. 


* Provide them with 
ways to share their 
story to support 
others to live 
healthier lives. 


-| The audience is living 
| a healthy lifestyle 


related to the SDOH 
and makes healthy 


3jehoióes. 2:17" 


* Sustain their actions 
by providing them 
with new ways to 
participate, access 
to more resources 
and tools. 


* Show them how 
their participation is 
making a difference 
personally and in 
their community. 


* Incorporate lessons 
learned into future 
planning. 


* Ongoing 
communications 
and updates. 


as well as ensuring everyone has an opportunity to 
learn about and participate in the development and 


evaluation of the technology, regardless of language, 


access to technology or other barriers. 


e show residents how they can be involved and use 
the technology and offer hands-on, interactive 
experiences. 


The CoA and AAHC are asking people to change 
their behaviour to become healthier and focus on 

the SDOH. We will frame communications with this 
focus and ensure we understand where an audience 
is at with what they think, feel, Know or are doing 
with regards to the technology, framed within the five 


stages of communications and our communications 


principles. 


What stage an audience is at will be determined by 
how much they Know about HealthSmart Airdrie, 
the information they would like to have access to and 
opportunities and barriers to using the technology. 
Table 6.1 provides the five stages of communications. 


STAKEN 


OLDER ANALYSIS SUMMARY 


We have completed an initial identification and analy- 
sis of stakeholders for HealthSmart Airdrie. As part of 
our planning process during project implementation, 
we will conduct a more detailed assessment, contact 
each stakeholder / group directly to discuss their 
interests and specific needs, and ensure we havent 
missed any stakeholders. 


Table 6.2 provides a summary of the stakeholders and strategies for stakeholder engagement and communications. 


General - Provide a variety of stakeholder engagement activities that will appeal to different 


- Includes a demographic mix ranging in age, 
socio-economic status, ethnicity and interests. 


- Resident interest, influence and impact are 
medium to high. Below is a break down of specific 
resident stakeholder groups. 


demographics. 


- Provide online stakeholder engagement opportunities through each phase, making it 
easy for people who are connected to participate. 


- Provide links to the online tools from the CoA's and AAHC's websites where residents 


already go for information. Leverage partner sites going forward. 


Youth = -— panes Provide youth with an opportunity to participate where they nang. out. E 


- may not participate i in d général stakeholder 
engagement session open to all residents. 


New to Canada and English 

as a second language 

— may not participate as asking for help or talking 
about needs may be a stigma in their culture. 
English may not be their first language and may 
be a barrier to participation. 


T Leverage the CoKs youth advisory group 1 to offer connections. 
- Work with community / culture champions and established service organizations to 
make connections and meet them where they are located. 


- Provide translators at events and materials in multiple languages to ensure residents 
can understand what is being asked and offer input. 


Indigenous — | -Work with ie Da champions ane CH service — ameatign o 


— may not participate in stakeholder engagement n 
activities because of literacy and education, ~ 
cultural differences, racism /discrimination — 

/ stereotypes, self-esteem, poverty and poor = 
housing, lack of transportation or child care. -> 
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make connections. - 


- “Provide them with easy an adesse opportunities to participate with diferent 
“prions in their nua, 
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Seniors 

— may not participate in stakeholder engagement 
activities due to mobility, lack of knowledge or 
access to technology and may not understand the 
benefits of or why they should make changes at 
this stage to live a healthier life (apathy). 


Single parents 
| may require child care in rder i to participate or 
may not participate because of the cost or fime 
commitment. 


Women 

- women make the majority of consumer decisions. 
Research shows that diversity of thought and 
perspective leads to better performance, better 
business strategies and stronger organizations as 
a whole. Women offen bring different perspectives 
and therefore can help eliminate blind spots. 


People with mental health issues | 

— may not participate for a variety of reasons - 
because of a lack of awareness, ability, and/or 
anxiety about participating and apathy. 


Homeless 
— may not participate because of discrimination, 


lack of transportation, lack of access to technology 


and may not understand how HealthSmart Airdrie 
can benefit them. 


People who don't have access to technology/no 
access to data or Wi-Fi 

— may not participate because of lack of access to 
technology and lack of understanding that they can 
participate 


Processed under the provisions of the Access to 


- Provide them with easy and accessible ways to provide input — including both paper | 


and technology-based methods. 


- Build an understanding of how easy the technology will be to use (show them) and 
the benefits to living a healthier life style now. 


- Include in-person activities throughout the project as seniors often prefer face-to- 
face conversation and the ability to ask questions. 


- Offer this group an opportunity to participate with their family and include activities 
for their children in a safe, child-friendly environment, at a time that works for them. 
This means hosting an open house outside of dinner hours, including information in 
.promotions about accommodating children and höstiig pop-ups in pus b 
venues such ds libraries anid rec c centres. 


- Include a de m to stakeholder engagement activities and consider gen- 
der-based factors fo gather input. 


- Offer specific opportunities for women to get involved in the design and testing of 
the technology, e.g., women focused stakeholder engagement sessions. 


- Apply a gender lens when seeking partnerships to develop and build the technology 
where possible. 


- Engage established service organizations to determine strategies to best engage 
This group and make connections. 


- - Provide a variety of ways to participate so there are activities that are comfortable. 
and encouraging. | i 


- Provide them with easy and doccssibie ways to pditicipate show them polenta 
opportunities for how they can use and access the technology, and how participation 
will benefit them. 


- Work with community champions and established service organizations to make 
connections. 


- Meet them where they are using stakeholder engagement activities such as Streeter 
surveys, pop-up events, interviews and use of public kiosks. 


- Provide them with information about how they can participate using City-owned 
technology and in-person tools and let them know how participation will benefit 
them. 


- Ensure communications and promotions are not only digital such as roadside signs, 
posters, TV and radio ads. 
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Community Organizations - Provide them with information about ways that they can get involved and how 
Includes faith-based, youth, senior, crisis / addiction, participating can benefit their organizations and the people that they support. 
health and wellness, housing, Indigenous, immi- | | 

grant, financial, recreation, arts and associations / — | ~ Provide workshops during the business hours to accommodate representatives of 
society / clubs and are either not-for-profit, non-profit | these organizations. 

or social enterprises. This group also includes 

support organizations in Calgary that Airdrie and 

area residents rely upon. These organizations 

provide residents with the resources and supports 

they need, often free or for a small fee. Often these 

groups have limited time and resources. 


Their impact and interest are high, influence 
medium to high. 


Local/Provincial Businesses ket | - Provide them with information about how they c can get involved and be port of 

Includes retail, health and wellness, restaurants and - HealthSmart Airdrie. | 

providers of services such as financial institutions. _ 

These companies provide paid services to residents. - Provide a variety of ways fo shat input to accommodate different interests and 
| M rl Dr Aa à schedules. y | 

Some of the business may be interested in becom- 

ing a partner in HealthSmart Airdrie. 


Their impact and influence are medium and interest 
medium to high. 


Educational Institutions - Provide them with information about how education fits within the SDOH, the 


Includes elementary to high school, post secondary | technology and how participating can benefit their organization and help the people 
and adult education. they support. 


Their impact and influence are high and interest - Provide a variety of ways to share input to accommodate different interests and 
medium to high. schedules. 


Alberta Health Services (AHS) | PPE Lae, . | - Provide them with an opportunity to partner in the project. To respect the unique 
Provides health care to residents and is a partner ~ | concerns AHS might have, provide opportunities to talk to the project team outside of 
with the AAHC in developing the FE health public events. 

information resource platform. eS ud 


AHS impact and influence are Uu and interest - 
medium. 


Primary Care Networks, Tr and Health - Provide them with information about how they can get involved and the benefits for 
Providers them and their patients. 


Highland PCN supports primary health care in | | | 
the community with strategies and resources for - Provide multiple ways to share input and make stakeholder engagement easily 


health that support physician practices. Airdrie also accessible to accommodate shift workers and demanding schedules. To respect the 
has a range of community health and health care unique concerns this group may have, provide opportunities to talk to the project 


professionals, typical of any community. team outside of public events. 


Their impact and influence are high and interest 
medium to high. 


Surrounding Municipalities - | - Provide them with information about the project, ask them lo Us involved, keep them 
Includes the MD | of View, Balzac and The Ciy informed and offer opportunities for partnership. | 


of Calgary. | 
- Offer opportunities for one-on-one interviews and opportunities to talk to the é project | 


Their impact and interest are e medium ond their | “team outside of public events to accommodate out-of-town un 
influence low. | : eget oh E 
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Provincial Government 
Their impact, influence and interest are medium. 


Airdrie City Council 
Their impact, influence and interest are re high. 


City of Airdrie 

The CoA is a partner in the HealthSmart Airdrie 
initiative. It also employs 630 Airdrie and areas 
residents who may work on part of this program and 
may be asked by their family and neighbours about 
it or want to participate. 


Employee interest, influence and impact are 
medium to high. 


Airdrie & Area Health Cooperative _ 
The AAHC is a partner in the HealthSmart Airdrie 
initiative. It also employs eight Airdrie and areas 


residents who may work on part of this program, be | 


asked by their family and neighbours about it, or — 
want 10 participate. 


The AAHC also has inermes uti may be interested 
in HealthSmart Airdrie. . 


Employee interest. infiuence and impad dre 
medium to high. | 


Potential sponsors 
Organizations that are willing to provide in-kind or 
financial support fo the project. 


Their impact is medium, influence low and interest 
medium to high. 


Potential partners 

Organizations that are looking to take a leadership - 
role in the development, use, promotion, integration, 
etc. of the HealthSmart Technology. 


Their impact, influence and interest is high. 


p Provide them with information about the project, keep them informed and give them | 


opportunities to participate. To respect the unique concerns the Alberta Government 
might have, provide opportunities to talk to the project team outside of public events. 


: [= Provide them with information about the project, ask them for their help in getting - 
Citizens excited / participating and provide them opportunities to get involved.To 
“| respect the unique concerns the Airdrie City Council might have, Pr opportuni 
ae ties to talk to the project team outside of public events. | 


“Invite them to participate in public events so thay c can hear first hund what i is 
“important to residents about the technology. - 


- Provide CoA employees with information about the project, how the CoA is involved, 
how they can get involve and the benefits of being involved, and information to help 
answer questions. 


- Invite them to attend public events fo provide input from both an employee and 
resident perspective. 


-| - Provide AAHC employees with information about the project, how the AAHC is - 


involved, how they can get involve and the benefits of being involved, and informa: | 
tion to help answer questions: | 


|» Provide them with information bout the project and the benefits a of geting involved, 


- Provide them with information about opportunities for sponsorship that are unique to 
their organization and how sponsorship can support and benefit their organization. 


- Reach out to develop porlhersnips with aligned organizations, 


- - Provide them with information about partnership opportunities that are unique fo 
their organization and how sponsorship can support and benefit their organization. — 
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Table 6.3 identifies several stakeholder engagement and communications risks, For the purposes of this proposal, we have only included the 
risks that ranked “high” in our evaluation criteria. 


Y TIONS RISKS 


Not identifying all the stakeholders / Not reaching all 


the stakeholders. 


Missed stakeholder groups can cause project 
delays, the perception of lack of transparency and 


stakeholder engagement, and lack of gathering the 


data required to build a technology that meets the 
needs of residents and stakeholder groups. 


Input not used in the development of the technology. 


Resident want to feel heard and will only use a 
technology that they feel like they had a part in 


creating. Also, the technology needs to meet the ~ um 


needs of the residents and show how it is Pan 
their needs. | 


Residents may feel their participation was a waste 


of time and may not support the technology. This 
may also lead to decrease in participation in 
future project and may lead to a distrust of bd 
HealthSmart Airdrie bias | À 


Keeping sustained interest "m plement 


tion and beyond / stakeholder burn out. 


HealthSmart Airdrie is a multi-year project that 
does not “come fo life” for citizens until two years 
into the project and is not fully built for five years. 
Stakeholders may lose interest or not "believe" the 
project is going to be implemented 


Reputation of the CoA | 
Reputation of the AAHC. 


Reputational issues may come up in a variety — 


of ways related to the money being spent, the — E 


technology not working, perceptions about lack of | - Provide key messages and coaching to project champions. 


transparency, privacy, security and/or stakeholder 
engagement, lack of connecting to all platforms, 
public promises. not Ey T around © | 
messaging, etc. 


Processed under the provisions of the Access to 


- Seek input from identified stakeholders about who else should be involved and 
included as part of the stakeholder identification task. 


- Ask stakeholders how they want to receive communication and how they want 
to be engaged, including channels / activities location and timing as part of the 
stakeholder analysis 


- Ensure citizens understand how the input they provide will be used. 


-. | - Report back on the input that was gathered, how the input was used to influence 


the design of the technology and, if input was not used, n it was iu used i in the. 
. development of the bed, 


- Build an understanding of the length of the project, phases and when they will have 
an opportunity to get involved. 


- Provide opportunities for meaningful stakeholder engagement and be strategic in 
ihe use of citizen's time to offer feedback. 


- Ensure communications is sustained between stakeholder engagement events. 


- Offer citizens ways to get involved that connects to the technology and offers them 
health-related benefits. 


- Develop a shared communication and stakeholder engagement plan with the 
Blue Zones Collaborative by integrating information and leveraging stakeholder 
engagement where possible. 


- Ensure the CoA and AAHC are aligned in their messaging and communications to 
stakeholders. 


- Create agreement about who i isa project Y 


- Ensure project team is aware of stakeholder engagement and coniniunications 


| plans and fiming. 
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Confusion / lack of coordination between programs 
— HealthSmart Airdrie, Blue Zones, Health Park, 
Needs-based networks, etc. 


Citizens may not understand or may be concerned 


with the multiple projects connected to HealthSmart 
Airdrie and may feel like the approach to stakeholder 


engagement and communications is uncoordinated 
and repetitive, or the stakeholder engagement 
efforts may cause participant fatigue. 


Lack of trust ofthe CoA / lack of trust of the AAHC. — 


Citizens may feel like they are” “being watched” or : E 1 Pet n pum. Ro D 
a ps : Provide aizen: witha an ibportünlly T: express their concerns, S provide input dd be: 


their data is being used for alternative pee 


They may have concerns with the CoA and/or - 


AAHC's ability to develop a technology of this scale. 


They may have had an experience w with the and/or | 
AAHC that has caused distrust. 


Inability to motivate end users to provide input 
on the technology / lack of interest / resistance to 
change. 


Citizens may be apathetic towards the project, may 
not have time to participate and/or may not be 
interested. 


- Ensure stakeholder engagement and communications of related projects is coordi- 
nated and aligned where possible. 


- Leverage events between projects. 


- Ensure the stakeholder engagement and communications representatives from each 
project are kept informed about plans. 


- Provide citizens with an understanding of how the projects are connected. 


| - Ensure citizens Un SM the breadth and eae of me projesi, the use eof data and 


security and DA 


part of design of the technology and what they need to be comfortable to use it. 


-Work with community champions to help « communicate about the project and ils. 
benefits. 


Pe | Address specific historical c concerns by listening, refecing oskng a anda answering 


when requested. - 
- Provide dien with multiple ways to participate, in a variety of ways and locations. 
- Provide them with information about the benefits of participating. 


- Show them how their input will be used and how their input has been used to 
design the technology. 


Figure 6.2 shows the IAP2 spectrum of public participation, inform, consult, involve, collaborate and empower. Our level for SCC Is involve. 


IAP2 SPECTRUM OF 


PUBLIC PARTICIPATION 
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Blue Zones has a stakeholder engagement process to 
gather input from residents and a process for engaging 
/ involving the community to focus on changing 
behaviours and participate in building a culture of 
health. The stakeholder engagement for HealthSmart 
Airdrie is specific to gathering input from residents 
about the technology, while at the same time, building 
awareness about the SDOH. Stakeholder engagement 
for HealthSmart Airdrie will be coordinated with 

the stakeholder engagement activities for Blue Zones 
including leveraging and scheduling of the events 


where possible. 


STAKEHOLDER ENGAGEMENT AC 


A variety of stakeholder engagement activities will be 
used throughout the implementation of HealthSmart 
Technology to provide residents and stakeholders 
multiple ways and opportunities to participate, in a 
manner that best suits their preferences. The tools 

are based on what has worked well in Airdrie in the 
past and new tools to ensure all stakeholders have 

an opportunity to provide input. We will offer a mix 
of in-person, in-situ and online opportunities that 
offer face-to-face and technology-based ways to have 

a conversation, learn about others ideas and offer 
feedback. Below is a sample list of key activities we will 
use to engage residents and will be modified for 
each stakeholder group. 


e Key Stakeholder Meetings 
/ Workshops — in each 
phase of the project, we 
will bring together 
representatives of 
the appropriate key 
stakeholder groups 
(for that phase) to 
give them an op- 
portunity to provide 
input, recognizing 
their involvement 
and concerns may 
be different than those 
of the public. Where 
possible we will meet with 
these stakeholders as a group, 
however some individual meetings 
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may be needed. Key stakeholders that we will 
include in these meetings are agencies, community 
organizations, educational institutions, Alberta 
Health Services, Primary Care Networks, the CoA, 
AAHC, Alberta government, and regional munici- 
palities. 


Open House - we will host an open house in Phase 
1 of the stakeholder engagement process that 

will include a graphic recorder to help illustrate 
stakeholders and residents vision for the technology 
and its outcomes. A summary report of the feedback 
received will be provided via the HealthSmart 
Airdrie website. 


Pop-Up Events — best practice and research indicate 
stakeholders are more likely to participate if we were 
to go to them. We will provide residents an oppor- 


tunity to have a conversation with the project team 


at popular gathering places in Airdrie, such as coffee 
shops, malls, theatres, parks, the library, Genesis 
Place (recreation facility) and grocery stores. 


Streeter Surveys / Interviews — this technique will be 
used to engage hard-to-reach individuals — such as 
vulnerable populations — and provide an opportuni- 
ty for people out and about to talk to team members 
doing interviews on the street. 


Online Opportunities - we know 

not everyone can attend, or wants 

to attend, a public open house. 

To ensure all residents and 
stakeholders have the same 
opportunity to provide 
input, we will mirror our 
face-to-face activities 
online. Residents can 
view the same 


materials online, then 
provide their input 
directly through an 
online tool hosted on 
HealthSmartAirdrie.ca, 
submit a feedback form 
via email, or they can leave 
feedback forms at a designated 
collection spots in their community 
such as City Hall or Genesis Place. 
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Table 6.4 outlines a list of sample communications tools that we will use throughout the various phases of the project. 


City Connections - newspaper insert Highway electronic billboard Radio ads 


Mayor's Radio Show - every Tuesday Signage at partnering locations TV - interstitials 
Airdrie Now newsletter — City business Signage at City facilities Media launch 
Airdrie Today — City newsletter Videos Media stories 
HealthSmart Airdrie social media HealthSmart Moment (radio, print) Celebration / launch event for community 
City of Airdrie social media Infographics Incentive campaign for participation 
City Council social media Email updates Blog / articles 
AAHC Social Media App / dashboard notifications Wellness challenges 
Influencer messaging HealthSmart Podcast 


Transit advertising/bus wrap 


e Kiosks — installed across the city where those who The communications activities ensure stakeholders 
are not digitally connected or are unsure about how are provided the information needed to participate in 
to use technology can use City-owned technology a meaningful way, to understand and to be aware of 
to provide their input, with guidance from on-site the opportunities available for providing input and to 
personnel. | receive information that is both clear and relevant to 

e Instastory Polls — social media will be used to M 
promote opportunities for stakeholder engagement, Communication and stakeholder engagement 
communicate important messages, and provide activities will be measured throughout this project 
quick polls that will help us to understand our using tools such as feedback forms, online comment 
residents needs. opportunities and by tracking against the schedule and 


goals. Measurements will indicate whether stakehold- 
ers understand the information that is being presented, 
whether enough information on the project has been 
provided in order to participate in a meaningful way, 
EVALUATION if participants can see how their input has been used, 
and if not why not, and whether the activities they 
participate in are perceived to be valuable to them. The 
plan and schedule may be revised based on evaluation 
results. 


What we Heard - a report back about what we heard 


in each phase of stakeholder engagement will be sent 
to all participants and will be made available online. 


A successful stakeholder engagement plan ensures ear- 
ly identification of issues of concern, areas of conflict 
and opportunities for the development of a technology 
that truly meets the needs of the community. It also 
ensures stakeholder time is used efficiently, and that 
the input received has been incorporated as much as 
possible; or if it hasnt been, stakeholders understand 
why not. 
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STAKEHOLDER ENGAGEMENT AND COMMUNICATIONS PLAN OVER\ 


Table 6.5 provides an overview of potential stakeholder engagement and communication plan phases. Based on the stakeholder analysis and 
confirmation of project timing, this plan will be updated and developed into a detailed workplan. 
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The Smart Cities Challenge (SCC) is being implement- 
ed under a partnership governance model between 
the City of Airdrie (CoA) and the Airdrie & Area 
Health Cooperative (AAHC) as outlined in Chapter 
5: Governance. The CoA and the AAHC recognize 
the various legislative / regulatory requirements 
surrounding the privacy of information. As the CoA 
is held to the higher standard with respect to privacy, 
the implementation phase will be managed under 

the Freedom of Information and Protection of Privacy 
Act of Alberta. For the purposes of the Act, the CoA 
will be the custodian of information. Where required, 
Albertas Health Information Act and other relevant 
federal and provincial legislation will be met. 


A Preliminary Privacy Impact Assessment has 

been completed and forwarded to the Office of the 
Information and Privacy Commissioner of Alberta 
(OIPC). We received initial feedback as outlined in the 
attached letter and have re-submitted the preliminary 
PIA in accordance with that feedback. Further 
discussions will need to occur prior to development. 
The CoA and AAHC are committed to working with 
the OIPC throughout development of the HealthSmart 
Technology. The preliminary PIA has shown that 
there is work needed to be completed in terms of 
formalizing specific policies and processes prior to any 
development work on the SCC program commencing. 
‘The CoA has committed to complete this work prior 
to year end. 
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Attached to the PIA is a PIPEDA self-assessment 
that demonstrates Airdries compliance to federal 
legislation. As outlined above, there are some under- 
lying policies and processes that have not yet been 
formalized at the CoA. 


The SCC project will be leveraged by all in the 
community. Aside from the main partnership between 
the CoA and AAHC, a series of partnerships will be 
created to share information ultimately breaking down 
information silos. For any partnership to be successful, 
there will need to be trust that information will be used 
responsibly, and the regulation of data, privacy, and 
security will be required throughout implementation 
and into the future. There will also need to be transpar- 
ency as to how data is used ad how it is protected, and 
users will need to have the tools to be able to control 
their own data and engagement with jointly generated 
content. 


Strong partnerships can attract additional interest, 
investment and participation from other companies, 
governments, agencies and non-profits and can show 


and encourage future collaboration. 


It is through the strength of partnerships that 
HealthSmart Airdrie will be a success. We will: 
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e Identify private, public and non-profit partners. 
» Involve everyone from the beginning. 


e Articulate the relationships between the partners 
— How do they or how can they support each other 
given our Challenge Statement to increase healthy 
life expectancy by 3+ years over 5 years? What do 
the partners have in common? 


Identify win-wins for the partners — What is the 
value proposition? Why would a partnership be 
beneficial? What are the potential partnerships? 


Identify expectations and requirements of the 
partnerships. Establish proper agreements, protocols 
and privacy requirements. Ensure alignment with 
vision, goals and objectives of the SCC. 


Establish formal agreements and accountability 
structures, including timelines, term and financial 
responsibilities. 


Establish a medium for collaboration and oversight 
— we want to be able to establish a system of collabo- 
ration across all partners. 


Determine the investment model — Who pays for 
what and on what terms? 


e Start small and early and build trust. 


More knowledge gives rise to better decisions. To keep 
innovating and keep partnerships alive, it is necessary 

to share Knowledge with everyone involved, including 
citizens. Our project will be a central clearinghouse 

. for connecting people, creating social cohesion 


and enabling sustained economic growth through 
knowledge. 


A knowledge-based city requires that each citizen 
takes responsibility for objectives, contributions to the 
city and for behaviour. This implies that all citizens 
are stakeholders of the city and have been provided 
opportunity for consent and transfer of knowledge. 
Knowledge management plays an important role in 
nurturing and building relationships and optimizing 
the flow of information. 


Our approach to knowledge sharing will be to 
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+ Establish a knowledge management strategy — 
knowledge sharing and a formalized plan for how 
information will be shared and protected are vital. 


Identify and define approaches for utilizing 
information to gather knowledge - Information can 
be explicit (extracted from data that flows as a result 
of the smart city) or tacit (generalized data about 
citizens and stakeholders). Knowledge is gained 
through a combination of both. 


Develop a clear stakeholder engagement and 
inclusion strategy for all stakeholders and citizens 

- knowledge becomes stronger with more involve- 
ment. À good stakeholder engagement strategy will 
maximize the ability to receive applicable informa- 
tion to increase knowledge. 


Data is "factual information (e.g., measurements or 
statistics) used as a basis for reasoning, discussion, 

or calculation" according to the Merriam-Webster 
dictionary. It has been referred to as the new currency 
or new fuel and is integral to HealthSmart Airdrie 
project and its users’ decision-making ability. Data 
allows users to stay on top of trends, answer problems, 
and analyze new insights. Relevant data needs to come 
together for the user to meet a common focus / goal / 
objective and provide actionable insights. 


There are many different types of data including 
personal data (anything specific to an individual), 
transactional data (anything that requires an action 
to collect), Web data (anything that is available on the 
internet), and sensor data (anything produced by the 
Internet of Things). Data can provide strategic insight 
and answer the what, where, why, when and how for 
any process and the security and management of it is 
essential for a smart city. 


MyAirdrie provides a single sign-on that allows users 


to authenticate to the Community Operating System 
(COS) and display COS dashboards and information 
through embedded and encrypted technologies. It is 
an existing system managed by the CoA independent- 
ly of the SCC. MyAirdrie Portal collects credential 
information to allow for signup (email address and 
password). MyAirdrie uses account verification to 
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ensure email addresses are valid. Passwords are stored 
as a hashed value and cannot be reverse-engineered 
externally or internally. During sign-up, input of a first 
and last name is optional and used only for personaliz- 
ing the login page. 


Stored data by the COS is for the verification, security, 
mapping, and utilization of data only. The SCC project 
will not be a collector of data; therefore, the life cycle 
of data will not need to be managed. As outlined in 
Chapter 4: Technology, the COS will be an enabler of 
secure and private data sharing. There is no intent to 
create a data repository to store data. The premise for 
the project is to bring together disparate data sources. 


ims 


Figure 7.1 shows the COS Data Life Cycle — create, store, use, 
share, archive and destroy as a repeating process. 


« Create - COS will connect to existing data sources to 
enable data flow. Data will not originate or be created 
by the COS. 


e Store - COS will temporarily store data as data 
requests are made by users. Temporarily stored data 
is de-identified. 


+ Use - COS enables data from disparate data sources 
to come together to inform users with meaningful 
content. 


e Share - COS enables sharing of data between users. 


e Archive - COS does not archive or store any identifi- 
able or individual data. Configuration and mapping 
data is archived and saved over time. Aggregated 
data, used for benchmarking, may also be archived. 
This is also de-identified. 
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e Destroy — Temporary data is destroyed as soon as 
the user request and/or session is ended. 


Partnerships will be entered into to acquire knowledge 
for data sharing. These external data sources will be 
required contractually to comply with their governing 
privacy legislation and ensure they have the legal au- 
thority to collect, use and disclose their data. PIAs will 
need to be completed and accepted by the OIPC prior 
to any API being activated. It is the responsibility of 
the data source to ensure proper consent is obtained or 
de-identification of the data occurs. The collection use 
and disclosure of data will remain their responsibility. 


A series of information mapping and supporting 
databases will be stored on a server in Canada. 

These databases will contain information, such as, 
the transactional ledger, algorithms, data maps and 
configuration details. All ledger information will be 
encrypted. Some aggregated, non-identifiable data 
may be stored to allow for baseline analytics and 
comparative benchmarking. Through the MyAirdrie 
Portal or the HealthSmart App, users will be able to 
access the COS, connecting to information shared by 


external parties. 


De-identification occurs when the direct and known 
indirect identifiers of data have been removed or 
manipulated to break the linkage to real world iden- 
tities (Future of Privacy Forum). Wherever possible, 
data is to be protected de-identified prior to entering 
the API. This means the data would be de-identified 
and protected by safeguards and controls. An authen- 
tication key will come with the de-identified data and 
will allow the data to be displayed once matched with 
the users authentication key. If an external source does 
not de-identify data, the API will contain a processing 
tool ensuring all identifiable data is removed prior 

to flowing through to the COS. In this instance, an 
authentication key will come through with the data, 
which when matched to the user's authentication key, 
will cause the data to be displayed temporarily on the 
users dashboard. Once a session is closed, all data will 


be removed from the system. 
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As discussed in Chapter 4: Technology, the project 
will be built as a private blockchain using open source 
technologies and be freely available to other commu- 
nities to use and customize to meet their own needs. 
Blockchain is a secure method allowing data to go to 
only those parties that have been authorized to access 
it. Authentication, access and security are achieved 


through blockchain technology. 
With the COS, other communities will receive: 


« A profile administration tool for users providing 
them with the ability to manage their account 
information, select the connected services they 
want to connect to and integrate with, share specific 
information with others, and view and manage their 
information access through a comprehensive audit 
log. 


Health dashboards will connect users directly to the 
data through visualization tools. Dashboard views 
can be customized to the user. Dynamic tools will 
be integrated to allow users to view data in different 
formats, across time and for their specific needs. 
Although Airdrie is using the dashboards for health, 
communities can design the dashboards for other 


purposes. 


A Master Application Programming Interface (API) 
allowing for a comprehensive data interchange. It 
will provide central mapping and an access point for 
data sharing. It will also be capable of de-identifying 
. information. 


COS modules will provide capacity for new and 
existing applications to connect with the COS. The 
modules will be any built-in or add-on functionality 
to the COS. An example is the Smart Service Inven- 
tory (SSI) being developed as part of this proposal. 
The SSI will be an available module for any other 
community to use. As the COS is replicated in other 
communities, innovations and connected modules 
created in one community can be shared and utilized 
in another. 


A recipe book will be provided to communities to 
provide them with a roadmap on how to leverage 
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what Airdrie has done for their community. Examples 
include: 


e How to build and leverage upon the SSI as a 
foundational directory of community information. 
An interface and smart functionality will be built 
allowing organizations to access, input and collabo- 
rate on an inventory for their community. 


Insights and gamification will be available, providing 
motivation for participation and engagement. 
Gamification encourages healthy competition across 
the community, fostering behaviour change. 


Providing the code required to connect and integrate 
data with the COS App. Airdrie is focusing on 
activity and fitness tracking (FitBit, Google Fit, 

etc.), health and wellness measurement (established 
by Alberta Blue Cross), community connections, 
community involvement and micro-credentialing, 
and eMental Health. 


BER à 4 


As outlined in Chapter 4: Technology, accessibility and 
usability of the COS is core to the technology. There 
will be three main access points to the HealthSmart 
App: the MyAirdrie Portal, native mobile apps and 
kiosks, located in strategic locations throughout the 
city. Each access point facilitates user connectivity. 


Interoperability is a key function of the COS. Increased 
interoperability, innovation and shared expertise will 
be achieved as the COS will be compatible with a wide 
array of development languages. Ihe COS API further 
fosters interoperability through defining protocols and 
standards for system connectivity and information 
sharing. This will enable the COS to work with other 
apps, platforms and devices like what Google, Ama- 
zon, Apple and others have successfully done. 


Security and privacy will be central to the development 
of the HealthSmart Technology, and include specific 
strategies as outlined in Chapter 4: Technology. Several 
risks have also been considered. A System Security 
Plan will be developed complying with best practices 
identified by leading security experts. Chapter 6: 
Engagement describes the significant stakeholder 


engagement in the development and implementation 
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of the technology. Concerns raised by users, residents 
and stakeholders will be considered and, where 
appropriate, built into the System Security Plan. 


Identify sources or stakeholders that may have access 
to applicable data and data elements required to 
produce value. It is about targeting and then providing 
the ability to act on findings. The four kinds of data 
(personal, transactional, web and sensor) need to be 
combined into content. 


e Identify partners (e.g., Stats Canada) and implement 
existing data standards (e.g., The International Open 
Data Charter). Establish a common data structure 
that can be reproduced and used across other 
communities and a balanced approach to acquisition 
and tie acquisition to our Challenge Statement. 


Establish a secure and private data use strategy. 

Data is the most important asset for all stakeholders 
including citizens. Security and privacy are essential. 
Ensure technology, policies, and protocols are all in 
place prior to any data use and users, residents and 
stakeholders have input into the strategy. 


Make data accessible. Create a data visualization 
strategy. Individuals, groups, organizations, and the 


community need to be able to view, analyze, and 
ultimately act on the collected data. Empower and 
engage users. Foster a data feedback loop to increase 
data use. Link content to the right questions. When 
producing content, provide the means to trace the 
results back to key data elements. Content must be 
timely when needed. 


The value of data is realized when it links to 
predefined goals. Value increases using visualization. 


Data value can be measured using tools such as the 
Data Value Index. 


Businesses and organizations must deal with risks, 
many of which have the same characteristics as those 
encountered elsewhere in life. To place risk in the 
proper business context, risk is defined as follows: Risk 
is the possibility that an event will occur and adversely 
affect the achievement of an objective. 
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The gold standard of risk management process models 
is considered the ISO/CSA 31000 Risk Management 
Standard. The ISO 31000 Risk Management-Principals 
and Guidelines Standard definition of risk is: The effect 
of uncertainty on objectives. As outlined in Chapter 3: 
Project Management, the risk management program 
components include: 


e Plan Risk Management 

e Identify Risks 

« Perform Qualitative Risk Analysis 

e Perform Quantitative Risk Analysis 
e Plan Risk Responses 

e Implement Risk responses 

e Monitor and Control Risks 


(Source: PMBOK Sixth Edition) 


Expanding on the risk mitigation and response strate- 
gies outlined in Chapter 3: Project Management, there 
are seven key aspects to managing risk: 


]. Risk Acceptance - informed decision to accept the 
likelihood and consequences of the risk 


2. Risk Transfer — shift responsibility to another party 
e.g., insurance 


3. Risk Elimination - find solution(s) to eliminate risk 
as consequence would be unacceptable 


4. Risk Increase - informed decision to increase a 
particular risk e.g., cost of managing risk outweighs 
its impact 


5. Risk Reduction - implementation of appropriate 
tools/techniques/processes to reduce the likelihood 
of risk and/or its impact 


6. Risk Avoidance - informed decision to not become 
involved in risk situation or cease activities because 
risk is too high 


7. Residual Risk - after risk treatment, determine if 


remaining risk is acceptable, if not other actions may 


be needed 
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A risk management framework and guidelines have . — of the project. A risk register has been created and is 
been completed that establish a standardized approach being populated. 
towards risk as we move through implementation 


Table 7.1 identifies the risks with respect to privacy and data. | = 


Unauthorized use of personal Ensure information is only accessible to those who need to know. Leverage IT and security protocols to 
information by internal protect personal information. 


or authorized parties or | | l | —— | | m 
unauthorized parties Unauthorized use by internal parties will result in disciplinary action (up to and including termination). 


Ensure any access by authorized external parties is protected under contract. 


Unauthorized use by external authorized parties may result in contract termination and any remedies 
available under the contract. 


All COS Users are assigned a unique User Id. 


All COS users are subject to COS standards. These may include: 
o Code of Conduct 

o Information Access and Acceptable Use Policies 

o Confidentiality Statement 

o COS User Agreement 


All COS users complete annual continuing education modules that include information privacy and 
security awareness. 


Logging and auditing are implemented within the production environment of the COS and users are 
advised their activity is audited through the User Agreement. 


Breaches are reported and investigated according to policies. a 


Apply information security classifications to each data element in all data assets connected through 
the COS. This will enable more efficient auditing as well as assist in classifying information products 
appropriately. 


Unauthorized collection, use, | * - Conduct periodic system penetration tests. 


or disclosure of personal: 
information by external | Unauthorized use by external authorized paris wil result in contact termination and any remedies z 


parties ue 2 Mn available under the contract. Y uu eee RM a T 


^L External parties/consultants a are subject to cos standards and agreements, These may include: 
| 0 COS User Agreement — ET | 
Po -COS Data Manager Agreement - : 
IT Access poorest rond | 


a Access fo authorized users ‘within the COS i is based ¢ on the need-to-know w principle (authorized u users 
| MAI have limited access to data according to their role). | 


: | A quarterly n review of individuals who have accessed the cos will be validated d against the list of 
| authorized COS users by the COS Administration. | 


: “ISAs have been established to limiti use and disclosure of cos data connections by external users. 


Le Users are provided with information that an approved external data : source is under an agreement as 
| y well as PE on any imitations f for i use and/or disclosure within the le agreement. | 
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Loss, destruction, or loss of Only authorized users have access to personal information. 


use of personal information | 7 | | | | 
Education / training on the importance of managing personal information appropriately. 


Adherence to information security classification protocols. 
Use of data and services will all require detailed ISAs. 
Only authorized system administrators control access rights to the COS. 


As the COS application is managed by the joint governance structure of the CoA and the AAHC, the 
COS follows the standard CoA backup / archival policies and CoA Antivirus implementation. In the 
event of accidental loss of data, the administrative data (mapping/ algorithms/ configurations, etc.) can 
be re-created / recovered. 


The core COS environment is read only for anyone except system administrators. 


Contractor or business = |- Ensure that any parties that information is shared with are authorized to do so. | 

partner collects, uses, or — Vau | | 
discloses personal informa- Authentication protocols require both authorized user and authorization from external data source. 
tion in contravention of FOIP . : 
or CoA policies 


Use of Blockchain technology Covered i in Chapter 4: non | m 


Hacking at source, corruption | * Data musi be protected during transit and while at rest. 

in API, accessing data while | ^. 

in transit or at rest - À For protecting data in transit 256-bit encryption will be applied t to all sensitive data prior rto moving and 
->| will use encrypted connections (HTTPS, SSL, TLS, FTPS, etc.) to protect the contents of data in transit. 


Requirements for PIAS and compliance w with privacy legislation i is enforced. 


Cybersecurity *. Work with existing, recognized cybersecurity organizations and experts to create a detailed, compre- 
hensive cybersecurity framework and incident response plan. 


Se 
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The goal of the finance administration function for our 
Smart Cities Challenge (SCC) proposal is to manage 
the financial and budgetary functions associated 

with the delivery of the said proposal issued. Our 
project will encompass, the delivery of a Community 
Operating System (COS) as described in Chapter 4: 
Technology. The Financial Management Function will 
fall under the collaborative structure with the partner- 
ship between City of Airdrie (CoA) and the Airdrie & 
Area Health Cooperative (AAHC). 


The comprehensive project budget can be found in 
Appendix B. The budget aligns with the project plan 
and spans across the five-year implementation period; 
direct and indirect costs have been identified. Project 
outcomes will be delivered through two main avenues; 
one being an established development team and 
secondly, the vendor delivered COS and associated 
Application Programming Interfaces (APIs). Each of 
these components are described below including the 
basis for budget estimates. Other areas of expenditures 
have been detailed within the third section and relates 
to elements of governance, supporting specialists/ 
experts and other supporting costs. 


DEVELOPMENT TEAM 

As identified within the technology plan, the develop- 
ment team will be responsible for delivering 

» MyAirdrie interface 


« COS preliminary assessment, detailed requirements 
and scope 
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e RFx process evaluation and selection 


« The Service Inventory VI - V4 
e System implementation 
e Mobile apps development V1 — V4 


A team of six net new staff that include a program 
manager, project manager, two developers, data analyst 
and a business analyst will be needed to complete these 
outcomes. An agile method of development will be 
employed, and key technical roles will be brought on 

as work ramps up. The projected budget has taken a 
simplified approach and shows full year costing for 
these positions. It is expected that work will ramp up 
quickly. 


e Salary cost estimates have been drawn from the CoA 
compensation models and are based on 2019 current 
rates for the identified positions. Benefit rates have 


also been from the CoA historical averages. 


« A Consumer Price Index (CPI) factor of 296 has 
been applied to each year; this assumption has been 
made by considering the fall 2018 economic outlook 
prepared by The City of Calgary. "Ihe Calgary & 
Region Economic Outlook 2018-2023' predicts CPI 


rate increases year over year with a range of 1.8- 2 96. 


In addition to the development team, financial, admin- 
istrative and engagement supports have been included 


in personnel resources budget. 
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COMMUNITY OPERATING SYSTEM 
Delivery of the COS represents the single most 
costly expenditure within the proposal. This indeed 


represents a technology solution, that will act as the 


foundation to enable achievement of our Challenge 
Statement. 


Chapter 3: Project Management describes the 
procurement process that will be undertaken to secure 
a contract for service. The overall cost is projected to 
be $5.5 million with $2.7 million expected to be spent 
within the first year. 


Our final submission speaks to the reguirement of 
vendor resources to meet the software development, 
communication and engagement, and external audit 
functions. Software development costs have been esti- 
mated at $4.5 million with a $2.5 million commitment 
in year one and $500,000 each year for the next four 
years and were estimated through consultation with 
three software development firms. Throughout the 
consultation phase, the developers have been provided 
with a clear objective for the intended purpose of the 
software, and the requirement of replicability in other 
communities. Communication and engagement costs 
have been estimated at $500,000. These estimates 

were generated through consultation with a local 
professional services consultant with specialty services 
in both communications and engagement. 


A hand full of other direct and indirect costs will be 
needed to deliver on the outcomes. As shown within 
the project plan, the CoA and AAHC subject matter 
experts will be inputted throughout the five years as 
associated with the work plan. 


The development team will need to be housed together 
physically. A complete lack of available space within 
the CoA and AAHC requires us to include costs for 
leased space. For the purpose of budget development 
lease rates and average operating costs were calculated 
at $26 and $6.50 / SQ FT respectively (Source: City of 
Airdrie Economic Development). Commercial Lease 
rates range from $24-$30/SO FT and average operat- 
ing costs for this space ranges from $5-$8/ SO FT). The 
space reguirement has been estimated at 900 SO FT. 
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Training costs, supplies and office space overhead 

have been considered and estimated for the project. 
Overhead costs have been estimated at 8% of projected 
budget excluding technology contract. 


An annual external audit is expected to be a reporting 
requirement. These costs have been estimated at 
$160,189. These costs are clearly identified in the 
project budget under the following activity types; 
governance, legal, privacy and risk, procurement, 
implementation, and IT. 


FINANCIAL TOOLS, ACCOUNTING 

AND INTERNAL CONTROLS 

As the grant dollars will flow to the CoA, the CoA 
will excise the role of steward over public funds. The 
management, recording, distribution and reporting 


to the Federal Government will be the responsibility 
of the CoA. As a mid-sized Alberta municipality, the 
CoA has in place systems, governance and processes to 


meet this responsibility. 


The CoA adheres to generally accepted accounting 
principles for local government established by the 
Public Sector Accounting Board and is published by 
the Chartered Professional Accountants of Canada. 
The accrual basis of accounting is used. 


As detailed within Chapter 3: Project Management, 
the project will be delivered in line with best practice 
project management methodology. The CoA adheres 
to standard project methodology in accordance with 
the Project Management Body of Knowledge (PM- 
BOK’) with adaptations to align with public organiza- 
tional practices for use of public funds, approvals and 
procurement legislation. Section 7 of the project plan 
demonstrates the elements of internal control with the 
requirement to: 


+ Have scheduled standardized project team meetings 
* Document agendas and meeting minutes 
e Scheduled project status updates 


e Ensure project status reports conform to standard 
templates including budget updates, timeline 
updates, risk identification and mitigation strategy 
identification 


… * Schedule sponsor meetings 
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Monthly reporting will be required to the Steering 
Committee. This reporting will include project status 
updates, as delivered by the Program Manager and 
quarterly budget updates as delivered by finance staff. 


Both the CoA and the AAHC are committed to 

the successful delivery of the project plan and it is 
anticipated that in-kind contributions will continue 
throughout the five-year span. Ihe project plan has 
identified where specific expertise will be drawn from 
each of the organization, however, the success in this 
project. Table 8.1 and Table 8.2 indicate anticipated 
in-kind contribution throughout the implementation 
phase. The CoA will keep track of and include these 
costs in the reporting requirements set out by Infra- 
structure Canada. 


Waith HN 


A Fi d VARI sini 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


City of Airdrie 
In-kind Resources 
Implementation Phase 
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Table 8.1 shows the in-kind resources that will be provided 
by the CoA during the implementation phase. 


WE 
- “Advisory C Committee 
“member, champion, - 
: leadership and strategic 
direction. 


Director Office of the CAO 

~ leadership and direction 
to legislative and legal 
services. Ensure compliance 
to legislation, partnership 
agreement and contract 
oversight. 


Director of Corporate Services — 
— leadership and direction 
technology, finance, and 
accounting. - 


Intergovernmental Liaison 

- liaison between the munici- 
pality, AAHC, other community 
organization and various 
levels of government. 


Manager Information Technol- - 
ogy — leadership and direction 


to technical staff. 


Various other CoA 
departments such as 
planning, engineering, parks, 
public works, community 
development, social planning, 
recreation facilities. Expertise, 
data and input as aspects of 
SDOH are explored. 


City Council — support and 
champion 


Table 8.2 shows the in-kind resources that will be provided by the 
AAHC during the implementation phase. 


AAHC CEO . 

In-Kind = “Advisory C Committee. 
Resources member, champion, - 
Implementation Phase | leadership and — Aue 
Strategic direction. pn D 


CFO - Financial ase. 


Board Members 


— Advisory and health Expertise, 
— Champions and support. — 


Specialists 
~ Health, risk and privacy, 
subject matter ener 


Research and - 
administrative. supports 


PERFORMANCE MEASUREMENT TOOL 
AND BLUE ZONES ~ $3.5 MILLION IN-KIND 


As indicated within our SCC application and demon- 
strated in Chapter 2: Performance Measurement, the 
Blue Zone initiative will play a significant supporting 
role to achieving project outcomes. 


A performance measurement tool specifically adapted 
to measure overall health and health outcomes will 

be developed. The specific and targeted approach 

to developing this tool will be accessed through a 
partnership between the AAHC and Alberta Blue 
Cross. Performance measurements used in the Blue 
Zones initiative will support our SCC initiative and 
our Challenge Statement. The total estimated value of 
this measurement tool is $3.5 million and has equal 
importance to both AAHC initiative and the SCC. For 
the purpose of in-kind valuation, it will be assumed 

to be one half of the valuation to the AAHC and the 
program and as such, the valuation will be recorded at 
$1.75 million for our SCC initiative. 


Stakeholder engagement and a process for engaging 
/ involving the community put forward by the Blue 
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Zones Project will be leveraged. This will ultimately 
provide synergies to effectively engage the population 
to focus on “Their Own Health? The engagement 
costs associated with the Blue Zones Initiative are in 
excess of $4 million. The in-kind valuation of this 
engagement strategy and implementation plan will be 


$2 million. 
REVENUE GENERATION 
=» OPERATIONAL PHASE 


Revenue generation for the purpose of long-term 


sustainability has and is actively being researched and 
explored. Potential revenue streams include: 


e The Customization of the open source software to 
meet the needs of particular clients 


e Paid apps and licenses for premium services above 
and beyond the base model operating system access 


e Advertising revenues, and sponsorship advertising 


While advertising revenues represent a good sustain- 
able revenue source, there will be a need for strategic 
alignment among potential advertisers with the overall 
objectives of the project and Challenge Statement 
outcomes. Sponsorship subtype advertising fits with 
the model of encouraging participation by unlocking 
rewards for users, based on actions within the system. 
These not only support the revenue generation for 
sustainability, but also encourage end user behaviours, 
supporting increases in overall health and health 
outcomes. 


In order to maintain the sustainability of the COS, 

the revenue streams will need to meet or exceed a 
target of $10,000 per month. This is expected to meet 
the estimated long-term annual operating budget 

of $120,000, for system maintenance and software 
upgrades. These anticipated maintenance costs are 
based on estimates through consultation with software 
development vendors. 
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RISKS AND MITIGATION STRATEGIES 


The CoA and the AAHC see the management of 
risk as an essential element to the successful delivery 
of the project plan outcomes. The CoA adheres to 
best practice project management methodology and 
standards status reporting at multiple level requires 


ongoing analysis of risk and identification of mitiga- 

tion strategies. AAHC is establishing risk management 

systems within their organization. Regular, expected 

review and reporting as described above, will manage . 
potential risk though the project life. Si 


Table 8.3 identifies typical risks of the project plan spanning over multiple years, and as the case with multi-year complex projects. 


Project Management: Unforeseen circumstances and their 


potential to jeopardize completion of project on time and on 
budget. 


Foreign Currency Risk: O | fluctuations i in n Foreign | 
Y” Rates. are Gi | 


Government: Changes in Government that have an unintended — 


adverse effect on the planning, ict ator and sustainabili i 


fy of the organization’ s initiatives. 


Vendor Management: Unanticipated deporte, MD or 
inability to complete contractual obligations. 


Project: An unanticipated change. in scope or other key criteria 
of a project that may. cause the € project to deviate from its 
original plan. - HU 


Resource Sustainability nat The inability to to attract, retain 
and increase capacity / knowledge of staff. 


Utilize best practice in project management to measure and 


monitor the project schedule and budget. Changes to scope, 
timing and finances will be authorized the Program Manager and 
the Advisory Committee 


_ | Negotiate all contracts for products and services in Canadian - 
| dollars. HIS Is ü risk avoidance strategy, t that transfers risk to a 
= | vendor. d j 


Economic Climate: Adverse changes in the economic climate. 


The environment will be righitoted regularly and ide in 
forecasts for CPI calculations and any market-based pricing 
used in the budget will be reported on through quarterly budget 
variance reporting. 


| Any changes i in Government. requirements for financial. reporting - 
and management ofthe project. will be addressed through a 0 
o structured change management process. | DE 


Vendors will be evaluated on their ability to nena asa’ "going 
concern.” Payments to vendors will be made on a percentage 

of completion basis, after meeting benchmark performance 
deliverables. Strong, comprehensive contracts will be established 
prior to the commencement of work. Procurement Specialists 
available through CoA will be consulted and will help guide this 
process. 


Any. change i in scope of work must be evaluated and documented | 
.| under the Change Management System, with approvals courting 
| by Program Manager and Advisory Committee as appropriate. - 


Effective recruitment efforts to ensure all resources are qualified 
and under contract for the life of the project as possible. Stan- 
dard human resource performance measurement methodologies 
will be implemented. 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


Page 269 of 341 


USE OF FINALIST GRANT 


The financial support provided through the finalist 
grant has been instrumental in facilitating the devel- 
opment of our proposal. A combined partnership 
approach was taken as use of grant dollars was 
established. This stage of the competition for the $10 
million was addressed through adherence to good 


project management practice. In order to work effec- 
tively in partnership, our SCC Advisory Committee 
and our SCC Management Team was established. ‘The 
Advisory Committee, having executive representation 
from the CoA and AAHC, had oversight and the 
Management Team was responsible to develop and 
deliver the proposal. Endorsement of the project scope 
as well as terms of reference occurred at the onset of 
the project and documented accountabilities and roles. 


As is evident with the Statement of Use that follows, 
the grant dollars were used to acquire needed expertise 


as related to communications, stakeholder engage- 
ment, legal and risk management. Both the CoA and 
AAHC leveraged existing staff to the best of our abili- 
ties and other services were secured where capacity or 
knowledge were not available through existing staff. 

A portion of the grant dollars was used to cover the 
cost of staff that were seconded to the project as well 

as funding for the required travel, printed material, 
stakeholder engagement events and meeting costs. The 
schedule below details the in-kind contribution for this 
proposal development phase. Project sponsorship as 
well as drawing on various subject matter experts was 
completed at the expense of the CoA and AAHC. 


The CoA, as the party responsible for the grant, had 
oversight to budget. On November 18, 2018 a budget 
adjustment was endorsed by Council. The CoA 
financial systems, processes and governance were 
used and adhered to, including requirement of public 
procurement. 


Figure 8.1 show the resource structure for our Smart Cities Challenge proposal development phase. 


Provide advice, — 
make recommendatio 
champion initiative 


Overall management 
coordination and | 
completion of proposa 
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STATEMENT OF USE OF GRANT 


Table 8.4 below shows how the grant funds were allocated during the proposal stage. Numbers have been rounded. 


City of Airdrie. | 
Smart Cities Challenge Initiative Proposal 


Finalist Grant Reporting © 
June 201 8 to April 201 ? 


sess ennu e a 
Budget perAppliction | 100000! 115000 36000) 250000 
Federal Grant — a wyd 6260000 bey Fr 
CI ERN RR RN [ [LL 


bens 


11 334 | ~ 56,669 


Development of Prototype © 


Travel one 13,210 14, 738 14, 738 MM NE 14, 738 


Promoton/events/publc e engagement - 


The application indicated the use of budget was to The original application budget made the best assump- 
be spread across the three categories: Governance, tions possible at the time. Governance and Technology 
Technology and Strategic. These three elements signify continued to be the two most significant elements. As 
the main components addressed through the develop- the project team progressed through proposal devel- 
ment of the proposal. The actual costs by object code opment, the sources used to pull together data needed 
have been allocated to the three categories in order varied slightly from the original application. 

to demonstrate how expenses lined up with original 

budget expectations. 
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IN-KIND CONTRIBUTION 


Table 8.5 shows the many different skills, resources and expertise were needed to complete the development of the proposal. 


In-Kind - ae (Chief — Ofce)-leudd | | | 4000 
Resources | | | “ 
CFO = Financial ou p E EH S E 
DE Direcfot 
Board Members — nen and health on o I i T 787, 
Specialists - m risk m privacy m | ; 
Research . ee ee ee UT 


Strategie jan | 


Total In-Kind Costs ANC = | $172,800 
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This program will remain evergreen, meaning we 
will periodically update and amend, based on lessons 
learned through evaluation of ongoing assessment 
activities. Throughout the implementation of this 
program, the City of Airdrie (CoA) will regularly 
review the program using the Gender-Based Analy- 
sis Plus (GBA+) model. In the detailed work plan for 
this project, we have accounted for the tracking and 
reporting of the actions outlined in this chapter to 
evaluate progress on an annual basis. 


The CoA together with the Airdrie & Area Health 
Cooperative (AAHC) are committed to strengthen- 
ing relationships with our Indigenous, First Nations, 
and Metis peoples through continued relationship 
building and consultation. Consultation is a 

process intended to open lines of communication 

to understand and consider the potential positive 
and adverse impacts of anticipated CoA decision on 
First Nations’ Treaty rights, with a commitment to 
address concerns and make accommodations where 
possible. 


As outlined in Chapter 6: Engagement, the CoA will 
use the International Association of Public Partici- 
pation (IAP2) methodologies to guide stakeholder 


engagement with our citizens. 
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The CoA is committed to using the Alberta Union a 
of Municipal Associations Welcoming and Inclusive 

Communities toolkits, the Status of Women’s 

Gender Based Analysis Plus methodology, and the 

IAP2 methodologies. To ensure all our community 

is represented in our stakeholder engagement, 

communications, and outreach, has access to our 

program, and has full support of the municipality, 

we are using a mixed model approach. 


We have a unique opportunity for our municipality 
to create employment and procurement prospects 
for a broader group of citizens. The CoA continues 
to create employment and procurement oppor- 
tunities, both directly and via positive spill-over 
opportunities for members in our community who 
face labour market barriers. There are three main 
strategies we will employ to ensure this objective is 
met: 1. targeted employment strategy; 2. proactive 
procurement for Community Operating System 
(COS); and (3) curriculum development and 
training to meet current and future labour market 
demands. 


The CoA and AAHC are committed to recruiting 
the best and brightest to join our teams. The 
HealthSmart Technology system and monitoring 
will require a sizable team to be employed. There 
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are many people in our community who have the . available to other Airdrie citizens looking to re-train 
skills and qualities that will enrich our organizations, | and re-skill, and to other jurisdictions. 

many who face labour market barriers including | 
discrimination. Working with our social agencies, 
community networks, and social enterprises, we 
will initiate a targeted employment strategy that 
will reach out to Indigenous peoples, women, 


The CoA is committed to sharing this technology 
with all our citizens and will promote its use and 
applicability by sponsoring regular hackathons. 
These hackathons will be open to all citizens and 


persons with disabilities, veterans, youth, and recent aini DDR preneur sprit We wi 


immigrants. We understand that persons from 
these groups face various barriers to apply for jobs 


work directly with the school divisions to promote 
these events and challenge our youth to use the 
skills learned in the co-developed curriculum. 
HealthSmart Hackathons will challenge our 
community to develop a new set of high-demand 
transferable skills that will meet TH employment 
reguirements. 


within Airdrie, and we will use multiple strategies to 
remove or address those barriers. 


The HealthSmart COS, is a smart information 
exchange software that will be developed m 
the CoA and AAHC. This COS will 


function as a hub connecting 


users and our citizens, 
efficiently and effectively to 
the services in the com- 
munity, allowing them 
to meet their health-re- 
lated goals. The CoA 
is committed to 


The CLA does not pertain 
to the Airdrie Smart 
Cities Challenge (SCC) 
proposal. The total 
cost of projects with 
a primary focus 


supporting procure- on climate change 
ment opportunities adaptation, resilience, 
that will be focused disaster mitigation, 


on small and medium or a reduction in 
enterprises (SMEs), and 
specifically SMEs with a 
depth of knowledge about 


our local community. 


GHG emissions is less 
than the $10 million 
threshold. 


To enrich the COS, the CoA 
will support the production of 
HealthSmart Apps through several programs 
and opportunities aimed at short- and long-term 
skill development to meet the ever-changing labour 
market demands. Some of the programs that the 
CoA will back include curriculum development, 
programming training, and hackathons. 


The City of Airdrie Values, a formal recognition 

of the values held by the CoA to all its citizens and 
employees, outlines the vision, mission, and core 
values. The CoAs vision statement states “Airdrie is 
a vibrant, caring community rich in urban amenities 
and opportunities for everyone. We value a healthy, 


Working with our local school divisions, we will build | sustainable environment connecting people and 

a curriculum focused on Information Technology . places” The CoAs Core Values are the heart of 
programing with a module on HealthSmart Apps. |. everything we stand for. Values that the CoA has 
This curriculum will build transferable skills in our | committed to include: Open Dialogue; Collaborative 
youth and prepare them for a future labour market. _ Relationships; Learning; Ownership; Innovation and 
Additionally, once this curriculum is developed, it can | Entrepreneurial Spirit; and Encourage the Heart. The 


be replicated in local government training courses, CoAs mission, Create-Serve-Care, was established 
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by the municipal employees and we are committed 
to achieving a corporate culture that supports these 
values. 


While the CoA does not currently have a spe- 

cific inclusion policy when hiring for leadership 
positions, we demonstrate our commitment to 
supporting the career advancement of women and is 
evident in the CoAs Senior Leadership Team that is 
comprised of three males and four females, and our 
SCC Management Team that consists of four males 
and seven females. 


The CoA will implement Gender-Based Analysis 
Plus training for all staff, including front line work- 
ers, boards, and committees who are working on the 
SCC initiative. This training is a key component of 
the CoAs commitment to the principles of inclusion 
and recognition of the value of diversity. 
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In addition, the CoA acts under all applicable 
legislation, including: 


- Alberta Municipal Government Act (MGA) 


» Agreement on Internal Trade (AIT) (referred to as the 
Canadian Free Trade Agreement as of July 1, 2017) 


* Comprehensive European Trade Agreement 
as of July 1, 2017 


e New West Partnership Agreement (NWPTA) 
e Applicable competitive bidding laws, and 


e Freedom of Information and Protection of Privacy Act 
(FOIP) 


The rules and regulations the CoA is held to under 
these various pieces of legislation are outlined in 


other chapters in this document. 
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APPENDIX A: LETTERS OF SUPPORT 
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Premier of Alberta 


Office of the Premier, 307 Legislature Building, Edmonton, Alberta T5K 2B6 Canada 


February 20, 2019 


His Worship Peter Brown 
Mayor, City of Airdrie 
400 Main Street SE 
Airdrie, AB T4B 3C3 


Dear Mayor Brown: 


Thank you for your letter regarding Airdrie's Smart City Application, and providing an 
overview of the health initiatives planned and underway. 


Congratulations on becoming one of the finalists in the federal government’s Smart Cities 
Challenge $10 million category. This is a significant milestone, and a reflection of the 
quality of the vision and initiatives within the proposal. Airdrie is an exciting and leading 
edge community and I look forward to keeping my eye on the results of this competition. 


| was also pleased to see that in addition to Airdrie, the city of Edmonton, and the 
combined proposal from Parkland, Brazeau, Lac Ste Anne, and Yellowhead Counties are 
also finalists in the $50 million and $10 million categories respectively. Alberta is well- 
represented in the Smart Cities program. 


Attached is a letter of support for your proposal. This letter complements the letter 
provided by Deputy Premier and Minister of Health, Sarah Hoffman. 


Thank you again for reaching out to me and best of luck in the competition. 


Sincerely, 


Rachel Notley 
Premier of Alberta 


Attachment 
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Premier of Alberta 


Office of the Premier, 307 Legislature Building, Edmonton, Alberta TSK 2B6 Canada 


February 20, 2019 


Honourable Francois-Philippe Champagne 
Minister of Infrastructure and Communities 
Suite 1100, 180 Kent Street 

Ottawa ON K1P OB6 


Dear Minister Champagne: 


| am pleased to express my support for Airdrie's finalist proposal for the Smart Cities 
Challenge $10 million category. 


The City of Airdrie has worked collaboratively over the past two years to engage hundreds 
of individuals and dozens of organizations to inform stakeholders and obtain community 
support in the development of this proposal. 


Becoming the first community in Canada to receive Blue Zone certification is particularly 
exciting, as it sets the stage for other communities across Canada to pursue this 
designation and achieve their health goals. 


We know that the social determinants of health play a major role in the overall health of 
individuals and communities. These determinants include lifestyle, income, housing, and 
sense of community. Blue Zone status, as well as the other projects identified in this 
proposal, focus on the social determinants of health and a whole community approach to 
proactively achieve greater health outcomes and guality of life. 


I encourage you to consider Airdrie's proposal for the Smart Cities $10 million category. 


Sincerely, 


a 
QUUM 


fi 


Rachel Notle 
Premier of Alberta 


cc: _ His Worship Peter Brown, Mayor of Airdrie 


Processed under the provisions of the Access to Page 280 of 341 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


Premier of Alberta 


Office of the Premier, 307 Legislature Building, Edmonton, Alberta T5K 2B6 Canada 


February 20, 2019 


Honourable Francois-Philippe Champagne 
Minister of Infrastructure and Communities 
Suite 1100, 180 Kent Street 

Ottawa ON K1P OB6 


Dear Minister Champagne: 


| am pleased to express my support for Airdrie's finalist proposal for the Smart Cities 
Challenge $10 million category. 


The City of Airdrie has worked collaboratively over the past two years to engage hundreds 
of individuals and dozens of organizations to inform stakeholders and obtain community 
support in the development of this proposal. | 


Becoming the first community in Canada to receive Blue Zone certification is particularly 
exciting, as it sets the stage for other communities across Canada to pursue this 
designation and achieve their health goals. 


We know that the social determinants of health play a major role in the overall health of 
individuals and communities. These determinants include lifestyle, income, housing, and 
sense of community. Blue Zone status, as well as the other projects identified in this 
proposal, focus on the social determinants of health and a whole community approach to 
proactively achieve greater health outcomes and quality of life. 


| encourage you to consider Airdrie's proposal for the Smart Cities $10 million category. 
Sincerely, 


d y 
E p 
A EE 


LE 


Rachel Notley 
Premier of Alberta 


cc: _ His Worship Peter Brown, Mayor of Airdrie 
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ALBERTA 
HEALTH 


Deputy Premier 
Office of the Minister 
MLA, Edmonton-Glenora 


AR 157016 


February 8, 2019 


Honourable Francois-Philippe Champagne 
Minister of Infrastructure and Communities 
. House of Commons 
: Ottawa ON K1A 0A6 


E: infc.minister-ministre.infc(g)canada.ca 
Dear Minister Champagne: 


I am pleased to provide this letter of support for Airdrie's finalist proposal for the Smart Cities 
Challenge for the $10 million category. 


The vision behind the submission of *Own Our Own Health — Becoming Canada's Healthiest 
Community" is an aspiration of many communities across Canada, but few have taken the 
difficult steps and engaged the right stakeholders, and identified the innovative solutions, to see 
this vision become a reality. 


Airdrie's submission focuses on bringing the community together, addressing the social 
determinants of health, and better utilizing the power of data analytics and technology to 
improve health outcomes. The impact that social determinants of health have on our overall 
wellbeing far outweigh that of the healthcare system. Blue Zone certification has demonstrated 
that to be an effective model for improving overall health and quality of life. 


Harnessing the power of information technology, and addressing the social determinants of 
health, are recognized by Alberta Health as strategic areas of focus for mitigating our growing 
healthcare costs and keeping Albertans healthier for longer. This is an ongoing challenge for all 
jurisdictions across Canada as we find new ways to deliver more value for our healthcare dollars, 
and care that is better aligned with the needs of communities. 


Realizing the full scope of work outlined in this proposal sets the stage for not only Airdrie to 
improve health outcomes, but through lessons learned and the acquisition of Blue Zone 
certification, benefit other communities across Alberta and Canada. 


m p, 


423 Legislature Building, 10800 - 97 Avenue, Edmonton, Alberta T5K 2B6 Canada Telephone 780-427-3665 Fax 780-415-0961 
10996 - 124 Street, Edmonton, Alberta T5M 0H8 Canada Telephone 780-455-7979 Fax 780-455-2197 


Printed on recycled paper 
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Honourable Francois-Philippe Champagne 
Page 2 


I encourage you to consider Airdrie as the successful recipient of the $10 million category. 


Minister of Health 


cc: _ His Worship Peter Brown, Mayor, City of Airdrie 
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po de 
ALBERTA 
ECONOMIC DEVELOPMENT AND TRADE 


Office of the Minister 
February 14, 2019 Deputy Government House Leader 
MLA, Edinonton-Beverly- Clareview 


AR 70233 


His Worship Peter Brown, 
Mayor 

City of Airdrie 

400 Main Street SE 
Airdrie, AB TAB 3C3 


Dear Mayor Brown, 


| am writing this letter to offer support for the City of Airdrie and Area's proposal to 
Canada's Smart Cities Challenge (CSCC). 


We understand that the CSCC encourages communities to adopt a smart cities 
approach to improve the lives of their residents through innovation, data, and connected 
technology. At its core, Airdrie’s proposal aims to increase the health and well- -being of 
rural communities through the full use of integrated data and connected technologies. 


The City of Airdrie’s holistic proposal aligns with several Government of Alberta 
priorities related to health outcomes, innovation, information, and communication 
technologies. The comprehensive proposal has the potential of generating social, 
economic, and environmental benefits for this region. 


Alberta’s Ministry of Economic Development and Trade is hopeful the proposal to CSCC 
will be successful given the benefit it will provide to residents throughout the region and 
the province as a whole. 


sincerely, 


Deron Bilous 
Minister of Economic Development and Trade 


425 Legislature Building, 10800 - 97 Avenue, Edmonton, Alberta TSK 2B6 Canada Telephone 780-644-8554 Fax 780-644-8572 


Printed os recycled paper 
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ww w.ab.bluecross.ca 


March 4, 2019 


Honourable Francois-Philippe Champagne 
Minister of Infrastructure and Communities 
House of Commons 

Ottawa, ON K1A 0A6 


Re: City of Airdrie Proposal — Smart Cities Challenge 
Dear Minister Champagne, 


Please accept this as a letter of support for the City of Airdrie (the City") and area's proposal for 
the Smart Cities Challenge. 


Alberta Blue Cross has made significant investments and takes great pride in our evolving focus, 
programs, and tools relating to the encouragement and facilitation of health and wellness. As with 
governments across our country, we know that only by measuring the health status of individuals 
and communities can we understand which inputs, interventions, and programs have a meaningful 
impact on the health and wellness of those individuals and communities. 


We support the City's focus on “Own Your Own Health" and “Becoming Canada’s Healthiest 
Community." Through such a focus, digital enablement of the residents and the community, and 
partnerships with organizations such as AAHC, we see tremendous opportunity for alignment with 
our values and the development of wellness approaches and tools. 


Alberta Blue Cross supports the City and AAHC in this endeavour. We are hopeful their proposal 
is viewed positively by the judging panel and is ultimately successful, given the enormous potential 
benefits to residents of the community, the province, and beyond. 

If you require additional information about Alberta Blue Cross. please visit our corporate website at 
www.ab.bluecross.ca, or contact me directly 


Sincere} 


President & CEO 


THE OFFICE OF THE PRESIDENT, RAY R. PISANI 
10009 108TH STREET, EDMONTON, ALBERTA, CANADA [51305 PHONI EE 
* The Blue Cross symbol and name are registered marks of the Canadian Association of Blue Cross Plans, an association of independent Blue Cross plans. Licensed to ABC Benefits Corporation 
for use in operating the Alberta Biue Cross Plan. " t Blue Shield is a registered trade-mark of the Blue Cross Blue Shield Association, ABC 10305 2016/05 
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: Airdrie & Area 
Health Cooperative 


March 1°, 2019 


TO review committee 
Re. Letter of Support from Airdrie & Area Health Cooperative (AAHC) for SCC Submission 


Airdrie & Area Health Cooperative (AAHC) has been involved as a collaborator in submitting the 
original proposal to the Smart City Challenge April 2018 and in preparing the submission being made 
March 5", 2019. 


This collaboration brings a unique community opportunity for the project: municipal engagement for 
health AND our organization focused on being a catalyst and support for a range of community 
initiatives toward the community vision of “Own our own health, becoming Canada’s Healthiest 
Community”. 


e The Smart City Challenge (SCC) Proposal is building on three years of community engagement 
related to developing a focus for health and optimizing a range of health and health care 
services to meet needs in new ways. It is directly supported by plans for continued community 
engagement toward our vision and the Challenge Statement for the SCC proposal. 


e The attached Impact plan sets out targets for the Community's Health Journey for 2019 to 
2025. It demonstrates: 


a. The commitment to three inter-connected strategies to “connect the dots for health”, 
with: 


i. The largest community engagement initiative to date, “Healthiest Airdrie, 
powered by the Blue Zones Collaborative”, targeted to launch Spring 2019 and 
continue over the next 3 to 5 years. 


ii. An intentional development of community capacity in support of healthy living. 


iii. An integration of initiatives to strengthen social determinants of health in the 
community. 


b. Theintent to meet community needs in new ways, including a range of cross-disciplinary 
initiatives, culminating in development of the Health Park, which will be developed as a 
smart community and be the hub for innovation related to digital health. 


c. The need to support the above with strategies with a digitally connected and enabled 
community, as would be advanced by the SCC. 


As outlined in the SCC proposal, AAHC will be involved in the Governance Committee to ensure 
connected strategies between SCC initiatives and the above community-related initiatives. 


The following resources requested in the SCC will be essential for AAHC to support the SCC project 
with health knowledge and integration of communication initiatives and messages in the community: 


e The IT Project Manager—a joint hire. 


e Financial Management—0.25 FTE/year 


Own Our Own Health 


Airdrie & Area Health Benefits Coonerative 
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Communications and Engagement SME to add to existing AAHC staff. ATIA - 20(1)(d) 


Contracted Services, including Health Consultant integrated with AAHC resources and joint 
‘decision-making regarding Risk and Privacy Governance. 


The community health initiative is su 


orted by funds that AAHC is bringing to the community. 


Finally, AAHC is the sponsor for a community oversight Council, Council Collaborating 4 Health. The 
terms of reference are attached. 


At their Feb 20" meeting, the Council endorsed the proposed initiatives in the SCC Challenge 
as a positive contribution to the Digital Health Strategy for the community. 


In closing, on behalf of AAHC Board and staff, we look forward to your consideration of the SCC 
submission being made by City of Airdrie and ourselves for this community. 


Yours truly, 


Attachments: 


Community Impact Plan—Being Developed with Council, Collaborating 4 Health 


Terms of Reference— Council, Collaborating 4 Health 
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TERMS OF REFERENCE 2019-2021—As of February 13, 2019 


PURG PROS GUA à od 


Umbrella council with accountability to the community—through reports to community and through AAHC 
Board and City. Operates as a support to community impact groups and system- wide development initiatives, 
making recommendations to back-bone/sponsoring organizations, AAHC, City, Other Sponsoring Org as required 


Over-arching goal: Champion community Vision, Mission and Outcomes in an informed, innovative, integrated, and 
impact-focused community—integrating Mayor's Declaration: 2019=Year for Healthy Living 
>> Vision: Own our own health, Becoming Canada’s Healthiest Community 
»»Mission: Creating a Community Healthy Culture where health - physical, menta and psychosocial health and 
where social determinants of health matter—and where individuals can own their own health " 
>> Outcomes: Engagement, Individual & Family Wellbeing, Health Outcomes, Improved Use of Resources | 


A. Champion a holistic view of development initiatives and opportunities, accelerating impacts toward our desired 
future, optimizing value-adding integration and learning as a community. 

e Seek opportunities for Council & community learning re our community and opportunities for health. 

e Develop and work with an annual implementation plan of initiatives that supports effective working 
relationships within the community and synergies across initiatives as possible. 

e Steward currency of the community plan for community initiatives with a minimum of Q 3years review to 
confirm need to investigate emerging areas of need or opportunity 

B. Foster an environment for success and impact of development initiatives. 
e Through discussion of project reports or proposals from community initiatives ( with their needs, 
opportunities for change, implementation and communication plans) 

> Build momentum through perspectives of value & opportunities for added impact through co- 
resourcing and opportunities to reduce duplication 
» Share potential creative ideas -- Have you thought about /heard about? 
» Understand Implementation timelines and alignment with other initiatives, etc 
>Make recommendations to Back Bone Organizations (AAHC, C ITY) and sponsoring organizations 

a. Endorsement 

b. Recommendations to enhance forward momentum & impact (co-resourcing; collaboration to 

reduce duplication; future considerations) OR for further work to improve viability and alignment 

>Confirm next steps (for master implementation plan) and if can profile project report on AAHC web site 

e Through discussion of new community-wide initiatives that are brought to the Council 

>Determine opportunities and synergies with existing initiatives as a guide to supporting proposed 
forward movement to Community Vision, Mission and Outcomes 
»Consider timing and linkages with other initiatives—and implications for overall plan. 
>Make recommendations to inform next steps with the initiative (value, further development & 
partners, implementation timing) 
C. Mobilize and support strategies for community citizens, organizations & partners to be aware of initiatives and 
have opportunities to connect with community-wide developments. 

e Gain from Council member connections to enhance citizen knowledge of community vision and mission and 
opportunities for health across the community, bringing to the Council areas of opportunity or concerns; 
Mobilize a communications plan and networks for conversations 4 health 

e Maintain community web resources; Complete an annual summary of progress per impact map. 

D. Co-Create a strategic impact map & key milestones for developing impacts and provide 
community-wide stewardship to advance Social Determinants of Health and Targeted Outcomes 
e Develop map over the first year ; complete in year 2 with outcomes data and initial work with Blue Zones. 
e Focus in year 2 on community outcomes through the work of the ABZ's Collaborative 
e Focus on social determinants of health in Year 3 based on work in year 2 as well as outcomes re well-being 


Processed under the provisions of the Access to Page 288 of 341 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


ATIA - 19(1) 
ATIA - 20(1)(b) 


--Typically 5 to 8:30 pm starting with a light supper, at AAHC Offices, allowing for 1-2 major discussions/mtg 

..Orientation Meeting Thursday, January 31, 2019 

..Quarterly: starting Wednesday, February 20, 2019, with third Wednesday of the month, except of Dec 
Wednesday, May 15t, Wednesday, Sept 18'^, Wednesday, Dec 4'^ 


e Members will be given an opportunity at the beginning of each meeting to declare potential for conflict of 
interest with agenda items. A member so declaring will be given an opportunity to absent themselves rom the 
discussion item. And this will be noted in minutes of the Council. 


e Terms of reference will be reviewed annually, at the February meetin 
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ABRIO HEALTH 


Our Community on the 
Move for Health 


“It is time to get innovative. Time to change the way we have been thinking and how we have been doing things. It 
is time to work collaboratively to make the system more responsive to the needs of Canadians. The time is now”, The 
Hon. Rona Ambrose, Former Minister of Health, Canada, Naylor Report 2015 


“ I am supportive of a grassroots approach to health,” Minister Hoffman, Alberta Health to Airdrie, Dec 2015 


“We need a new paradigm>>towards a wellness focus, team-based care, patient/family focused, community based 
care”, Dr. Verna Yiu, President, Alberta Health Services, Public Forum, January 2019 


DEVELOPING THE PLAN, DISCUSSION 1-FEB 


3RUARY 20, 2019, COUNCIL, COLLABORATING 4 HEALTH 
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VISION 
Own Our Own Health, Becoming Canada's Healthiest Community 


MISSION 
Creating a "Community Healthy" Culture where 
" Health = Physical + Mental + Psycho-Social Health and 
= Social Determinants of Health Matter and 
= Individuals Can Own Their Own Health 


OUTCOMES/GAINS FOR ALL 
Engagement, Individual & Family Well-being, 
Health Outcomes, Improved Resource Use 


Building on the past 3 years of momentum: Community work & collaboration for 24/7 Urgent Care April 2017, Stakeholder 
engagement leading to report, Together for Tomorrow, April 2018; Community engagement re Blue Zones May 2018 
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VISION and MISSION and OU 
STRATEGIES -2019-2015 


MEETING NEEDS IN NEW 
WAYS 


| ONNECTING THE DOTS , 
B I | FOR HEALTH 


" . BECOMING A DIGITALLY ~ 
CONNECTED & ENABLED Wu. 
€ v— V. à AND TECHNOLOGY | 
ooo  _  _ _ ENHANCED COMMUNITY | 
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STRATEGIES 


| CONNECTING THE DOTS FOR HEALTH NGA UTR o | _ MEETING COW UN NEEDS 
CONNECTED & ENABLED E | IN NEW WAYS _ o 
AND TECH-ENHANCED 


COMMUNITY 


** Community Engagement, Multi-sectoral 


** Needs- Based Coordination & Strengthening 
Development & Healthy Policy Improve 


of Community Capacity Improve Access, 


Well-Being, Health & Use of Resources L] Smart Community Information Wellbeing & Health 
..Healthiest Airdrie- BlueZones Collaborative, Creates Opportunities to ..Mental Health: 5 recommendations 
linking with strategies below “Own our own health; Own my .. Domestic Violence 
own health” ..Supportive Care 
** Collaborative Development of Community .. with CHIRP (Community Health ..Hospice Care 
Assets Optimizes Capacity for Well-being, Information Resources Other TBD 
Health & Improved Use of Resources Platform)) A í ; 
..Youth Strategy ..with Smart Service inventory, d THOS O to Integr ate Services & 
.. Activate Community for Aging in Community (TBD) with Smart City Challenge Streamline Delivery Improves Access, 
..Naturally Occurring Communities (eg schools, Applications 4 Health Health Impacts & Use of Resources 
| faith communities, neighborhoods for living, e.g. ABC Balance Tool ..MH: Youth MH Hub 
employers) -Well being Measure ..Healthy Aging in Community; living well 
...Linkages with System Digital with chronic conditions TBD 
$* Integrated Community Action on Social Health developments TBD „Other TBD 
Determinants of Health Improves Potential MH Digital Applications Enhance : 
for Well-being & Health Well-Being + Multi-sectoral Innovation and Partnerships 
| e Mental Health 


...Affordable Housing Strategy Create New Community Capacity for Health 


..Smart Service Inventory & System Navigation AED with Improved Access & Use of Resources 
i LJ Technology for Well Being | 
..SDOH Community Plan TBD ..Health Park 
TBD .. Others TBD 


ENGAGEMENT: to inform; to gain input; to co-innovate, co-develop, co-deliver; to assess impact 
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City of Airdrie 


Smart Cities Challenge Initiative -Proposal 


Five Year Financial Projections 


Development Team 
Program Manager 
IT Project Manager 
Developers 
IT Business Analyst 
IT Data Analyst 
Financial Expertise 
Administration & Engagement Support 
Total Development Team Salaries 
Benefits (estimated at 24%) 


Total Development Team Personnel Expense 


Contracted Services 
Technology Development 
Technology Implementation & Maintenance 
Specialists 
Communication and Engagement 
External Audit 


Total Contracted Services Expense 


City of Airdrie Staff Resources 
Governance, Legal, Privacy and Risk 
Procurement 
Information Technology 


Total City of Airdrie Staff Resources Expense 
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0.50] direct 


direct 
direct 
direct 


direct 


indirect 


indirect 


direct 
direct 
direct 
direct 


indirect 


indirect 


indirect 


indirect 


Year 1 


54,814 
116,129 
175,422 

87,711 

87,711 

31,452 

20,161 
573,400 
137,614 

711,014 


2,500,000 . 


100,000 
89,000 
7,000 
2,696,000 


17,225 
21,336 
4,725 
43,286 


Year 2 


55,910 
118,452 
178,930 

89,465 

89,465 

32,081 

20,565 
584,868 
140,368 

725,236 


500,000 
100,000 
100,000 
7,500 
707,500 


24,175 
1,500 
60,704 
86,379 


Page 295 of 341 


Year 3 


57,028 
120,821 
182,509 

91,255 

91,255 

32,722 

20,976 
596,565 
143,176 

739,741 


500,000 
100,000 
100,000 
7,500 
707,500 


Year 4 


58,169 
123,237 
186,159 

93,080 

93,080 

33,377 

21,395 
608,497 
146,039 

754,536 


500,000 
100,000 
100,000 

7,500 

707,500 


Year 5 


59,332 
125,702 
189,882 

94,941 
94,941 
34,044 
21,823 
620,667 
148,960 
769,626 


500,000 
100,000 
100,000 
7,500 
707,500 


2,850 


8,550 
11,400 


5 Year Totals 


285,254 
604,340 
912,903 
456,452 
456,452 
163,675 
104,920 
2,983,996 
716,157 
3,700,153 


2,500,000 
2,000,000 
500,000 
489,000 
37,000 
5,526,000 


47,550 
22,836 
89,804 

160,189 


1 of 2 


City of Airdrie 
Smart Cities Challenge Initiative -Proposal 


Five Year Financial Projections 


Other 
Office Space Lease 
Training and Training Travel 
Supplies and Miscellaneous 


Administrative /Overhead (at 8% excluding 
technology contract) 


Total Other Expenses 


Total Projected Expenses 
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indirect 
indirect 


indirect 


overhead 


Year 1 Year 2 Year 3 Year 4 Year 5 5 Year Totals 

29,250 29,250 29,250 29,250 29,250 146,250 

15,000 5,000 5,000 5,000 5,000 35,000 

5,000 5,000 5,000 5,000 5,000 25,000 

79,964 84,669 79,675 80,877 82,222 407,407 

129,214 123,919 118,925 120,127 121,472 613,657 

$ 3,579,513 $1,643,034 $1,575,616 $1,591,838 $1,609,999 $ 10,000,000 
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WBS 


1.6.1 
1.6.2 


174. 
1.7.2 


18 
1.9 
1.9.1 
1.9.2 
1.9.3 
1.9.4 
1.9.5 


1.1 


1.10.1 
1.10.2 
1.10.3 
1104 
1.10.5 
111. 
1.11.1 
1.11.2 
1.11.3 


11131. 


1113.11 
1413.12 
1.11.3.2 

1.11.3.2.1 


Task Name 
Smart Cities Challenge Implementation Plan 


| Governance 


Refine and finalize governance model for project implementation 


Create partnership agreements | 
Legal Review of partnership agreement 
Set up Program Steering Committee Structure 
. Create Terms of Reference 
_ Set up project team 
. . Confirm project roles — | 
. Determine staffing for project roles | | 
Determine organization agnostic tools for project use 
Determine document storage area &/or tools — | | 
identify retention periods for AAHC requirements and CoA 
requirements | | | AE 
Signature Approvals of partnership agreement - 


| . Annual External Audit of Funding Use 


Year 1 audit 
Year 2 audit 
Year 3 audit 
Year 4 Audit 
. Year 5 Audit 


Annual Community Employment Benefit Tracking and Reporting 


Tracking, assembling & reporting data 
Tracking, assembling & reporting data 
Tracking, assembling & reporting data 
Tracking, assembling & reporting data 
Tracking, assembling & reporting data 
Community Operating System (COS) Governance 
Determine COS governance scope 
Determine requirements | 
Procurement for Foundation Governance Consultant 
Prepare & Gather Quotes | | 
Provide requirements sheet and supporting documentation 


| for quotes . 


Contact consultants for quotes and provide scope of work 
and requirements 7 
Evaluation of Quotes _ 
Complete evaluation ensuring responses satisfy the defined 
acceptance criteria 


Smart Cities Challenge Proposal Project Plan City of Airdrie 
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_ 16 hrs 


Work 
28,740.42 hrs 
775 hrs 
7 hrs 

20 hrs 

37 hrs | 
Thrs — 
20 hrs 

12 hrs 

6 hrs” 

6 hrs 


6 hrs 
10 hrs 


2hrs — 
375 hrs 
75 hrs 
75 hrs 

75 hrs 

75 hrs 

75 hrs 


110 hrs 


22 hrs 
.22 hrs 
:22 hrs 
22 hrs | 
22hrs | 
169 hrs. 
10 hrs 
10 hrs 


| _ 43 hrs 
:7 hrs 


2 hrs 


5 hrs 


| 7 hrs 


6 hrs 


Duration 


1409.37 days 
1380 days 


5 days 


| _ :10 days 


35 days 
2 days. 


.10 days 


10 days 
5 days 


..:5 days 
:5 days 


3 days 
5 days 


5 days | 
1115 days 
15 days 


_ 15 days 


15 days 


_ 15 days. | 
:15 days 


1065 days 


_ o days 
:5 days 


5 days 

5 days 

5 days | 
125.73 days 
5 days 

5 days 
38.73 days 


| 6 days 
1 day 


5 days 


5,13 days 


5 days 


Start 
Tue 19-09-03 
Tue 19-09-03 


Tue 19-09-03 


__ Mon 19-09-09 _ 
‘Mon 19-09-23 


Thu 19-11-07 
Tue 19-11-12 


. Tue 19-11-26 
:Tue 19-11-26 
‘Mon 19-12-02 
Tue 19-09-03 © 
Tue 19-09-03 


: Tue 19-09-03 


Thu 19-11-07 


Fri 20-08-28 _ 


Fri 20-08-28 
Fri 21-09-10 


Fri 22-09-16 


Mon 23-09-18 
Fri 24-09-20 © 


Fri 20-08-28 


Fri 20-08-28 
Thu 21-08-26 


_ Fri 22-08-19 


Tue 23-08-08 
Tue 24-07-30 
Fri 20-09-11 
Fri 20-09-11 
Fri 20-09-18 
Fri 20-09-25 
Fri 20-09-25 


Fri 20-09-25 


Mon 20-09-28 
Fri 20-10-02 
Fri 20-10-02 
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Finish 


Mon 19-09-09 


Mon 19-09-23 


Thu 19-11-07 
Tue 19-11-12 
Tue 19-11-26 
Mon 19-12-09 


Mon 19-12-02 
Mon 19-12-09 
Mon 19-09-09 


Thu 19-09-05 


Mon 19-09-09 


Fri 19-11-15 - 
Thu 24-10-10 
Fri 20-09-18 

Thu 21-09-30 


Thu 22-10-06 


Fri 23-10-06 
Thu 24-10-10 


Mon 24-08-05 


Fri 20-09-04 


Thu 21-09-02 
Thu 22-08-25 
Tue 23-08-15 
Mon 24-08-05 
Thu 21-03-04 


: Fri 20-09-18 


Fri 20-09-25 


Wed 20-11-18 | 


Fri 20-10-02 


Mon 20-09-28 


Fri 20-10-02 


Fri 20-10-09 


Fri 20-10-09 


Predecessors 


Wed 24-11-20 — 
Thu 24-10-10 - 


Resource Names 


Risk Privacy and Governance CoA[19%] 


2. Risk Privacy and Governance CoA[27%] _ 


3 Legal Review — 


4 Risk Privacy and Governance CoA[47%] o 


| _ 5 Risk Privacy and Governance CoA[27%] 


6 Program Steering Committee[16%] 


8 Program Steering Committee[16%] — — 


| Program Steering Committee[27%] 


Risk Privacy and Governance CoA[27%] 


| 4 Risk Privacy and Governance CoA[5%] 


2FS+260 days 


15FS+260 days 


16FS+260 days 


17FS+260 days _ 
18FS+260 days 


. 2FS4260 days 
21FS+260 days | 
22FS+260 days. 


23FS+260 days 


:24FS+260 days 


13FS+220 days 


27 Risk Privacy and Governance CoA[27%] _ 


28 Risk Privacy and Governance CoA[27%] 


31 Risk Privacy and Governance CoA[13%] 


32 Risk Privacy and Governance CoA[16%] 


External Financial Auditors 
External Financial Auditors 
External Financial Auditors 
External Financial Auditors . 
External Financial Auditors | 


Intergovernmental Liaison CoA[61%] 
‘Intergovernmental Liaison CoA[61%] 
Intergovernmental Liaison CoA[61%] 
Intergovernmental Liaison CoA[61%] 
Intergovernmental Liaison CoA[61%] 


Risk Privacy and Governance CoA[27%] 


1 of 40 


WBS . Task Name. 

1.11.3.2.2 Discuss results and discrepancies from evaluations 
:1.11.3.3 Reference checks - 

1.11.3.3.1 Prepare reference check questions 
1.11.3.3.2 . Schedule reference checks — u 
1113343. . Perform reference checks - ask questions 
1.11.3.3.4 Determine Successful proponent 

1.11.3.4 Tentative award 

1.11.3.5 Approval of vendor 

1.11.3.6 Negotiate contract 

1.11.3.7 .. Award contract 

1.114 Consultant Report Creation — 

1.11.5 Review consultant COS governance report — — 
1.11.6 | Legal Review of governance recommendations 
1.11.7 ... Determine COS governance model 

2 Initiate - | 

21 ... Needs assessment | 

24.1 Confirm objectives 

2.1.2 Determine Stakeholders 

2.1.3 Determine scope 

214 . Create project charter. MM i 
2.2 < Program Steering Committee approval of project 
2:3 Project kick-off 

3 Assess/Envisioning l 

31i .. . Perform stakeholder assessment 

3.2 : Phase 1 Engagement & Communications 

3.2.1 Planning stakeholder assessment and plan 
3.2.1.1 Public consultation - key stakeholder meetings 
3.2.1.2 . Plan development 

3.2.2 Visioning & ideas for COS 

3.2.2.1 Communications & promotions 

3.2.2.2 Open House(s) 

3.2.2.3 Key stakeholder meetings 

3.2.2.4 . Streeter surveys 

3.2.2.5 . Pop-ups 

3.2.2.6 Online tool 

3.2.2.7 Kiosks | | | 

3.2.2.8 Phase 1 - what we heard report 


Smart Cities Challenge Proposa! Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


Work 
1hr 


5.5 hrs_ 


ihr 
Er. 
S3hrs. 


0.5 hrs 
7.5 hrs 
1hr 
15 hrs 
Ohrs 


| 80 hrs 


3 hrs 
20 hrs 


.3 hrs 


40 hrs | 
28 hrs 


.14 hrs 


6 hrs 
6 hrs 
2hrs — 
2 hrs 


10 hrs 


. 1,380.92 hrs 


6 hrs 


350 hrs 


40 hrs 


22 hrs 
18 hrs 


310 hrs 
56 hrs 
68 hrs 


| 44 hrs 
.22 hrs 


58 hrs 
34 hrs 
8 hrs 

20 hrs 


Duration 
1hr 
0.73 days 
1hr 


ihr 
3hrs 


0.5 hrs 
1 day 


1 day 


30 days 


.0 days 


30 days 


| day 


45 days | 

1 day 
11.96 days 
8.96 days 
5 days 
2.16 days 
0.8 days © 


_iday 
:2 days 


1 day 


309.5 days 
3 days 


78 days 
20 days 


.10 days 
:10 days 
.58 days 


10 days 
15 days 
8 days 

5 days 


10 days 


5 days 


..2 days 
:3 days 


Start Finish 
Fri 20-10-09 Fri 20-10-09 
Fri 20-10-02 Mon 20-10-05 _ 
Fri20-10-02 Fri 20-10-02 
 Fri20-10-02 Mon 20-10-05 
Mon 20-10-05 Mon 20-10-05 
Mon 20-10-05 Mon 20-10-05 
Mon 20-10-05 Tue 20-10-06 
Tue 20-10-06 Wed 20-10-07 
Wed 20-10-07 Wed 20-11-18 
‘Wed 20-11-18 Wed 20-11-18 
Wed 20-11-18 Wed 20-12-30 - 
Wed 20-12-30 Thu 20-12-31 
Thu 20-12-31 Wed 21-03-03 
Wed 21-03-03 Thu 21-03-04 
Fri 19-11-15 Mon 19-12-02 
Fri 19-11-15 Wed 19-11-27 
Fri 19-11-15 Fri 19-11-22 
Fri 19-11-22 Tue 19-11-26 
Tue 19-11-26 Wed 19-11-27 
Wed 19-11-27 Wed 19-11-27 
Wed 19-11-27 Fri 19-11-29 
Fri 19-11-29 Mon 19-12-02 
Tue 19-09-03 Thu 20-10-29 
Fri 19-11-29 Wed 19-12-04 
Wed 19-12-04 Fri 20-03-20 _ 
Wed 19-12-04 Fri 20-01-03- 
Wed 19-12-04 Wed 19-12-18 
Wed 19-12-18 Fri 20-01-03 
Fri 20-01-03 Fri 20-03-20 
Fri 20-01-03 Thu 20-01-16 
Thu 20-01-16 _ Wed 20-02-05 
Wed 20-02-05 Tue 20-02-18 
Tue 20-02-18 Tue 20-02-25 
Tue 20-02-25 Mon 20-03-09 
Mon 20-03-09 Mon 20-03-16 
Mon 20-03-16 Tue 20-03-17 
Tue 20-03-17 Fri 20-03-20 
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Predecessors 


Resource Names 


34 Risk Privacy and Governance CoA 


32 Risk Privacy and Governance CoA 


37 Risk Privacy and Governance CoA 


38 Risk Privacy and Governance CoA 


_39 Risk Privacy and Governance CoA 


40 Procurement CoA 


_ 41 Risk Privacy and Governance CoA[13%] 


42 Procurement CoA[796] 


7 43 Procurement CoA[7%] 


51,52,53 


43 Foundation Consultant[3626] 


_AS Risk Privacy and Governance CoA[40%] 


46 Legal Review 
47 Program Steering Committee[4096] 


| 13 Business Analyst[3796] 


51.Business Analyst[37%] 
52 Project Manager 
Project Manager[37%] — 
54 Program Steering Committee[13%] | 
Business Analyst[27%], Communications CoA[27%],Data 
Analyst[27%], Developer 1[27%], Developer 2[27%],Program 
55 Manager[279?6], Program Steering Committee[27%],Project 
Manager[27%], Technology and Security SME AAHC[2796], Technology and 


: Security SME CoA[2796] 


— 55 Business Analyst[27%] 


58 Communications and Engagement Consultant[80%] 
61 Communications and Engagement Consultant 


62 Communications and Engagement Consultant[13%] 
64 Communications and Engagement Consultant[13%] 


_ 65 Communications and Engagement Consultant[13%] _ 


66 Communications and Engagement Consultant[13%] 
67 Communications and Engagement Consultant[13%] 
68 Communications and Engagement Consultant[1396] 
69 Communications and Engagement Consultant[13%] 
70 Communications and Engagement Consultant[13%] 


2 of 40 


WBS 
3.3 
331 


3.3.2 


3.3.3 
3.3.4 
3.3.5 
3.3.6 
3.4 
3.4.1 
3.4.2 
3.4.3 


3.4.4 
345 
3.5 


3.5.1 
3.5.2 
3.6 

3.7 
3.7.1 
3.7.1.1 
3.7.1.2 


3.7.1.3 


3.7.1.4 
3.7.1.5 
3.7.1.6 
3.7.2 


3.7.2.1 


3.7.2.2 
3.7.2.3 


3.7.2.4 


3.7.2.5 


3.7.2.6 


Task Name 


Requirements gathering , 
Gather detailed requirements and priorities _ 
Information Governance & Management requirements and 

priorities | | 
IT requirements and priorities y 
Validate mandatory requirements 
Final requirements review 
Requirements approval 

Create business case 

_ Create project vision 
Ensure objectives are measurable 
Add detail to project scope 


Add project specific information into the business case 
Document use cases 
Program Steering Committee review & approval of business case 


Program Steering Committee review 
_ Program Steering Committee approval 
BSAStage 1 
__RFx Procurement — 
Prepare & Post RFx 
Submit formal bid request to procurement 
Build RFx document | | 
Provide reguirements sheet and supporting documentation for 


i RFX 


Post RFx 

RFx posting period — 

Create evaluation scorecard 

Stage 1 evaluation - mandatory _ 

Remove pricing information from RFP responses 

Place responses in the project folder _ 

Filter responses to those meeting all mandatory requirements 
based on vendor responses _ 

Create mandatory requirements evaluation sheets with 
acceptance criteria 

Email evaluators PDF of mandatory requirement responses and 


business unit evaluation sheet 


Complete mandatory evaluation ensuring responses satisfy the 


defined acceptance criteria 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


Work 
182 hrs — 


160 hrs 


5 hrs 


5 hrs 


4hrs 
6 hrs 
2 hrs 
62 hrs 


10 hrs 
Ohrs | 
:2 hrs 


10 hrs 
30 hrs 
6hrs 
4 hrs 
2 hrs 


2 hrs 
700.92 hrs 


:36 hrs 


1hr 
30 hrs 


2 hrs 
1hr 
Ohrs 

2 hrs 
69.5 hrs 


4hrs 
1hr 


1hr 


50 hrs 


Duration 


45 days. 


:30 days 


5 days 
5 days 


[4 days 


2 days 


i1 day 


30 days 


_.5 days 


5 days 
5 days 


5 days 


10 days. 


0.71 days 


| 0.47 days 
. 0.24 days 


1day . 
104.83 days 
56.13 days 


:1 day 


20 days 
2 hrs 


1hr | 


_ 35 days 


2 hrs 


41.27 days 
4 hrs 


1hr 


1hr 
4 hrs 


1 hr 


5 days 


- Start Finish ; 
Fri 20-01-03 Wed 20-03-04 
Fri20-01-03 Wed 20-02-12 
Wed 20-02-12 Thu 20-02-20 
Thu 20-02-20 Wed 20-02-26 
Wed 20-02-26 Fri 20-02-28 
“Fri 20-02-28 Tue 20-03-03 
Tue 20-03-03 Wed 20-03-04 
Wed 20-03-04 Wed 20-04-15 
Wed 20-03-04 Wed 20-03-11 
Wed 20-03-11 Tue 20-03-17 
Tue 20-03-17 . Tue 20-03-24 
Tue 20-03-24 Tue 20-03-31 
Tue 20-03-31 Wed 20-04-15 
Wed 20-04-15 Thu 20-04-16 
Wed 20-04-15 Thu 20-04-16 
| Thu 20-04-16 Thu 20-04-16 
‘Wed 20-03-04 Thu 20-03-05 
Thu 20-04-16 Thu 20-09-03 
Thu 20-04-16 Thu 20-07-02 
Thu 20-04-16 Fri 20-04-17 
Fri20-04-17 Thu 20-05-14 
Fri20-04-17 Fri 20-04-17 
Thu 20-05-14 Thu 20-05-14 
Thu 20-05-14 Thu 20-07-02 - 
Thu 20-05-14 Thu 20-05-14 
Thu 20-05-14 Thu 20-07-09 
Thu 20-07-02 Thu 20-07-02 
Thu 20-07-02 Thu 20-07-02 
Thu 20-07-02 Thu 20-07-02 
Thu 20-05-14 Thu 20-05-14 
Thu 20-07-02 Thu 20-07-02 
Thu 20-07-02 Thu 20-07-09 
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Predecessors 


(0737475 


Resource Names 


62 Business Analyst[71%] 

73 Business Analyst[13%] 

74 Business Analyst[13%] | u 
_ Business Analyst[27%] 

76. Business Analyst[40%] 

77 Business Analyst[27%] 


78 Business Analyst. 


. 80 Business Analyst[27%] 


81 Project Manager[5%] 
82 Business Analyst[2796] 
83 Business Analyst[40%] 


79 Program Steering Committee[13%], Project Manager - 
86 Program Steering Committee[1396],Project Manager - 


78 Corporate Information Governance Leads CoA[27%] 
85. 


85 Project Manager[13%] 
91 Procurement CoA[20%] 
91.Project Manager 


92 Procurement CoA[50%] 
94. 


| 92 Procurement CoA 


95 Procurement CoA 
98 Procurement CoA 


99 Procurement CoA 


94: Project Manager 


100,101 Project Manager 


102 


Business Analyst,Corporate Information Governance Leads CoA,Developer 


1,Technology and Security SME AAHC,Program Manager,Project Manager 


3 of 40 


WBS 
3.7.2.7 


3.7.2.8 


3729 


3.7.3 
3.7.3.1 


3732. 


3.7.3.3 


3.7.3.4 


3.7.3.5 


3.7.3.6 
3.7.3.7 
3.7.3.8 


3.7.3.9 
3.7.3.10 


37311. 


3.7.4 
3741 
3744.1 


3.7.4.1.2 


3.7.4.1.3 


Task Name 


Discuss results and discrepancies from stage 1 evaluation 


Update evaluation spreadsheet with stage 1 results 


PDF evaluation spreadsheet 
Stage 2 evaluation - core business requirements 
Create evaluation sheets with acceptance criteria 
Update evaluation sheets with proponent scores — 
Email evaluators PDF of core business requirement responses 


. and evaluation sheet | 


Complete requirement evaluation sheet ensuring responses 
satisfy acceptance criteria 


Meet with evaluators to discuss large disparities in scores 


Adjust scores based on common understanding 


Update evaluation spreadsheet with stage 2 scores 


Discuss results from stage 2 


Filter proponents to only those meeting % of business 
requirements 

Determine proponents proceeding to stage 3 

PDF evaluation spreadsheet 


Stage 3 evaluation - other requirements, corporate evaluation 
Other rated requirements 


Create evaluation sheets with acceptance criteria 


Update evaluation sheets with proponent scores 


Email evaluators PDF of business requirement responses and 
evaluation sheets 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


| Work 


7 hrs 


1hr 


0.5 hrs | 
75.83 hrs 


| 4 hrs 
1hr 


1hr 


50 hrs 


7 hrs 


7 hrs 


1 hr 


3.5 hrs 


0.25 hrs 
1hr | 
0.08 hrs 
167.83 hrs 
84 hrs 


4 hrs 
4 hrs 


1hr 


Duration 


1hr 


1hr 


| 0.5 hrs 


48.84 days 


:4 hrs 


1hr 


.1 day 


5 days 


1hr 


'1hr 


1 day 


30 mins 


15 mins 


30 mins 


5 mins 


54.99 days 


54.9 days 
1 day 


4 hrs 


Zhr 


Start 


Thu 20-07-09 


Thu 20-07-09 


— Thu 20-07-09 


Thu 20-05-14 
Thu 20-05-14 
Thu 20-07-09 


Fri 20-07-10 


Fri 20-07-10 


Fri 20-07-17 


Fri 20-07-17 


Fri 20-07-17 
Mon 20-07-20 


Mon 20-07-20 


Mon 20-07-20 
Mon 20-07-20 


Thu 20-05-14 
Thu 20-05-14 
Thu 20-05-14 


‘Mon 20-07-20 


Tue 20-07-21 
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Finish 


Thu 20-07-09 


Thu 20-07-09 
Thu 20-07-09 


Mon 20-07-20 - 


Thu 20-05-14 - 


. Fri 20-07-10 


Fri 20-07-10 


Fri 20-07-17 


Fri 20-07-17 


Fri 20-07-17 


Mon 20-07-20 
Mon 20-07-20 


Mon 20-07-20 


Mon 20-07-20 
Mon 20-07-20 


Tue 20-07-28 


Tue 20-07-28 


Fri 20-05-15 


Tue 20-07-21 


Tue 20-07-21 


Predecessors. 


Resource Names i 

Business Analyst,Corporate Information Governance Leads CoA,Developer 
103 1,Technology and Security SME AAHC,Program Manager,Project 
Manager,Procurement CoA 


104 Project Manager 
105 Project Manager 
_ 94 Project Manager 
106 Project Manager 
109 Project Manager 
Business Analyst,Corporate Information Governance Leads CoA,Developer 


110 
1, Technology and Security SME AAHC,Program Manager,Project Manager 


Business Analyst[13%],Corporate Information Governance Leads 
CoA[13%],Developer 1[13%], Technology and Security SME 
AAHC[13*6],Program Manager[1396],Project Manager[13%],Procurement 
CoA 

Business Analyst[1396],Corporate Information Governance Leads 
CoA[13%], Developer 1[1396], Technology and Security SME 
AAHC[13%],Program Manager[13%],Project Manager[13%],Procurement 
CoA 


113. Project Manager 


Business Analyst,Corporate Information Governance Leads CoA,Developer 
114 :1,Technology and Security SME AAHC, Procurement CoA, Program 
Manager, Project Manager 


115 Project Manager 


116. Procurement CoA,Program Manager 
117 Project Manager |. 


94 Project Manager 
117,121 Project Manager 


122 Project Manager 


4 of 40 


WBS Task Name 


Complete requirement evaluation sheet ensuring responses 


3.7.4.1.4 . "m 
satisfy acceptance criteria 
3.7.4.1.5 Meet with evaluators to discuss large disparities in scores 
3.7.4.1.6 Adjust scores based on common understanding 
37447 Update evaluation spreadsheet with rated requirements 
VARI ‘scores | 
3.7.4.2 Corporate evaluation 
3.7.4.2.1 Create evaluation sheets for corporate evaluations 
37422 Email evaluators corporate evaluation sheets - 
3/7423 Complete corporate evaluation 
3.7.4.2.4 Meet with evaluators to discuss large disparities in scores 
3.7.4.2.5 Adjust scores based on common understanding 
3 5 ie y Update evaluation spreadsheet with corporate evaluation 
Ar scores _ 
3.7.4.3 Discuss results from stage 3 
3.7.4.4. Determine proponents proceeding to stage 4 
3.7.4.5 PDF evaluation spreadsheet 


3.7.5 | Stage 4 evaluation - reference checks" 


3.7.5.1 Prepare reference check questions 

3.7.5.2 Schedule reference checks 

3.7.5.3 Perform reference checks - ask questions 

3.7.5.4 — Take notes regarding responses 

3.7.5.5 Update evaluation spreadsheet with reference check results 
3.7.5.6 PDF evaluation spreadsheet | 

3.7.6 | Stage 5 evaluation - demonstrations 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Rêvisê en vertu de la Loi sur l'accês 
a l'information 


Work 


60 hrs 


7 hrs 


7 hrs 


1hr 
80 hrs | 
4 hrs 
ihr 


60 hrs 


7 hrs 


7 hrs 


1hr 


3.5 hrs 


0.25 hrs 
0.08 hrs 
8.58 hrs . 
3 hrs 

1 hr 


3 hrs 


1hr 
0.5 hrs 


0.08 hrs - 
263.58 hrs 


‘Duration 


5 days 


ihr 


‘thr 


hr 


54.37 days _ 


4 hrs 


1hr 


5 days 


1hr 


ihr 


1hr 


30 mins 


| :7.5 mins 


5 mins. 


_ 56.16 days 
ihr 
iday 


1hr 


‘hr 


15 mins 


5 mins 


:21.54 days 


Start 


Tue 20-07-21 


Tue 20-07-28 


Tue 20-07-28 


Tue 20-07-28 


Thu 20-05-14 - 


Thu 20-05-14 


Mon 20-07-20 


Tue 20-07-21 
Mon 20-07-27 


Mon 20-07-27 


Tue 20-07-28 


Tue 20-07-28 


Tue 20-07-28. 
Tue 20-07-28 


— Thu 20-05-14 


Tue 20-07-28 
Wed 20-07-29 
Wed 20-07-29 


Wed 20-07-29 


‘Wed 20-07-29 
Tue 20-07-28 
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Finish 


Tue 20-07-28 


Tue 20-07-28 


Tue 20-07-28 


Tue 20-07-28 
Tue 20-07-28 
Thu 20-05-14 


Tue 20-07-21 


Mon 20-07-27 


Mon 20-07-27 


Tue 20-07-28 
Tue 20-07-28 


Tue 20-07-28 


Tue 20-07-28 | 


. Tue 20-07-28 


Wed 20-07-29 
Thu 20-05-14 


Wed 20-07-29 _ 


Wed 20-07-29 


Wed 20-07-29 
Wed 20-07-29 


. Wed 20-07-29 
Tue 20-08-25 


Predecessors 


Resource Names | 

Business Analyst[27%],Corporate Information Governance Leads 
123 CoA[27%], Developer 1[2796], Technology and Security SME 
AAHC[27%],Program Manager[2796],Project Manager[27%] 
Business Analyst[13%],Corporate Information Governance Leads 
CoA[13%], Developer 1[13%], Technology and Security SME 
AAHC[13%],Program Manager[1396],Project Manager[13%],Procurement 
CoA[1394] 
Business Analyst{13%] Corporate Information Governance Leads 
CoA[13%], Developer 1[13%], Technology and Security SME 
AAHC[13%],Program Manager[13%],Project Manager[13%],Procurement 
. CoAL13%] —— 


124 


125 
126 Project Manager 


94. Project Manager 
117,129 Project Manager - 


Business Analyst, Corporate Information Governance Leads CoA,Developer 


130 
1,Technology and Security SME AAHC,Program Manager,Project Manager 


“Business Analyst,Corporate Information Governance Leads CoA,Developer 
131 1,Procurement CoA,Program Manager,Project Manager, Technology and 
Security SME AAHC . — — | oe EN A bi 
Business Analyst,Corporate Information Governance Leads CoA,Developer 
132 1,Procurement CoA,Program Manager,Project Manager, Technology and 
Security SME AAHC . 


133 Project Manager 


Business Analyst, Developer 1,Technology and Security SME 
127,134 AAHC,Procurement CoA,Program Manager,Project Manager,Corporate 
Information Governance Leads CoA 
135 Procurement CoA,Project Manager 
136 Project Manager 


94 Procurement CoA,Project Manager,Program Manager 


136,139 Project Manager 


140 Procurement CoA,Project Manager, Program Manager | 
140 Project Manager 


142. Procurement CoA,Project Manager 


143 Project Manager 


5 of 40 


WBS — Task Name 
3.7.6.1 | Create demonstration package 
Meet with project team to discuss scenarios for the 
3.7.6.1.1 | 
demonstration 
3.7,6.1:2 Document scenarios | | a" 
3.7.5.1.3 Determine scenario and break schedule 
3.7.6.1.4 Review and approve demonstration package 
3.7.6.2 WR | Schedule demonstrations | | 
3.7.6.3 : Send demonstration packages to proponents _ 
3.7.6.4 Demonstration preparation period — - 
3.7.6.5 | Create demonstration evaluation sheets 
3.766 | Determine scoring matrix 
3767 Meet with evaluators to review demonstration process and 
y scoring matrix 
37.68 | | Demonstration Logistics 
3.7.6.8.1 Schedule rooms 
3.7.6.8.2 Coordinate snacks and water 
3.7.6.8.3 Order lunch (opt) 
3.7.6.9 Attend and evaluate vendor demonstrations 
3.7.6.10 Meet with evaluators to discuss large disparities in scores 
3.7.6.11 Update evaluation spreadsheet with stage 5 scores 
3.7.6.12 Discuss results from stage 5 
3,7013 Determine proponents proceeding to stage 6 
3.7.6.14 PDF evaluation spreadsheet 
3.7.7 Stage 6 evaluation - pricing 
3.7.7.1 Create spreadsheet comparing total cost of ownership 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


Work 


45 hrs 


14 hrs 


20 hrs 
EU 


7 hrs 


1hr 


1hr 
20 hrs 
4hrs 
ihr 


7 hrs 


4 hrs 
Thr 
‘2 hrs 
:1 hr 


147 hrs 


28 hrs 


1hr 


3.5 hrs 


1 hr 
0.08 hrs 


77.58 hrs. 


2 hrs 


Duration 


_ 7.13 days 


1 day 


5 days 
'1day. 


1hr 


1 day 
uhr. 
:10 days 
4 hrs 
0.5 hrs 


1hr 
2.13 days 
1 day 


1 day 
1hr 


3 days 


1 day 


1hr 


30 mins 


30 mins | 


.5 mins 
6.28 days 


1 day 


Start 
Tue 20-07-28 - 


Tue 20-07-28 


Wed 20-07-29 
Wed 20-08-05 


Thu 20-08-06 


Tue 20-07-28 


Thu 20-08-06 
Thu 20-08-06 


— Thu 20-08-06 
— Thu 20-08-06 


Thu 20-08-06 | 


Wed 20-07-29 


Wed 20-07-29 


Thu 20-07-30 - 


Fri 20-07-31 


Wed 20-08-19 


Mon 20-08-24 


Tue 20-08-25 


Tue 20-08-25 


Tue 20-08-25 
Tue 20-08-25 
Tue 20-08-25 


Tue 20-08-25 
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Finish 


Thu 20-08-06 


Wed 20-07-29 


Wed 20-08-05 


Thu 20-08-06 


Thu 20-08-06 


Wed 20-07-29 


_ Thu 20-08-06 
Wed 20-08-19 


Thu 20-08-06 
Thu 20-08-06 


Thu 20-08-06 


Fri 20-07-31 


Thu 20-07-30 
‘Fri 20-07-31 
Fri 20-07-31 


Mon 20-08-24 


Tue 20-08-25 


Tue 20-08-25 


Tue 20-08-25 


— Tue 20-08-25 
Tue 20-08-25 


Wed 20-09-02 
Wed 20-08-26 


Predecessors 


Resource Names 


Business Analyst,Corporate Information Governance Leads CoA,Developer 


127,117 1,Technology and Security SME AAHC, Procurement CoA, Program 


Manager,Project Manager _ 


| 147 Business Analyst{53%], Project Manager[53%] 


148 Project Manager | | | 
Business Analyst,Corporate Information Governance Leads CoA, Developer 

149 1,Technology and Security SME AAHC,Procurement CoA,Program l 
Manager,Project Manager 

136 Project Manager 


150,151 Project Manager 


152 Vendor[27%] | 
150 Project Manager 


| 150 Procurement CoA,Project Manager 


Business Analyst,Corporate Information Governance Leads CoA,Developer 
155 1,Technology and Security SME AAHC,Procurement CoA, Program 
Manager,Project Manager 


_ 151 Project Manager 


158 Project Manager _ 
159 Project Manager 


Business Analyst[93%],Developer 1[93%], Technology and Security SME 


153,154,156 AAHC[93?6], Procurement CoA[9396], Program Manager[93%],Project 


-Manager[93%],Corporate Information Governance Leads CoA 


Business Analyst[93%], Developer 1[93%],Technology and Security SME 
161 AAHC[93%],Procurement CoA[93%],Program Manager[9394],Project 
Manager[93%],Corporate Information Governance Leads CoA[93%] 


162 Project Manager 


Business Analyst,Corporate Information Governance Leads CoA, Developer 
163 1,Technology and Security SME AAHC,Procurement CoA,Program 
Manager,Project Manager 
164 Procurement CoA,Project Manager 
165 Project Manager . 


165 Project Manager[27%] 


6 of 40 


WBS 


3.7.7.2 


addo 


3.7.7.4 


3775. 


3.7.7.6 
3.7.8 


Task Name 


Evaluate pricing and assign scores 


Update evaluation spreadsheet with stage 6 scores 


Discuss results from stage 6 


Determine successful proponent 
____ PDF evaluation spreadsheet _ 
__ Tentative award 


BSA Stage 2 


Solution approval 


Negotiate contract _ "c 
Legislative Services review of contract. o 
Confirm sizing and resourcing needs for the project 
PIA/PRA 

Update existing PIA/PRA 

Submit PIA. A 

PIA/PRA accepted by OIPC 


Add detail to project schedule for implement and go-live phases 


Financial setup for project 
Create GL cost centre | 
Move funds from pool to project GL 
Complete paperwork required for Paramount (opt) 
Create vendor in Paramount (opt). 
Create PO in Paramount | 
: Execute contract 
Implement 
Community Operating System (COS) 
Design i 
Design complete _ 
Development/Configuration 
. Testing © MW 
Redevelopment for bug fixes 
_Retesting — 
Testing passed 
Training 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accês 
a l'information 


Work 


70 hrs 


1hr 


3.5 hrs 


Thr 
0.08 hrs 
2 hrs 


6 hrs 


3 hrs 


15 hrs 
20 hrs 
4 hrs 
4 hrs 

2 hrs | 
1hr 
1hr 


14 hrs 


5 hrs 
1hr 
1hr 


‘hr 


1 hr 
1hr 


1 hr 


24,481.5 hrs 


:3,753.5 hrs 
:300 hrs 
:7.5 hrs 


922 hrs - 
35 hrs 


| 87.5 hrs 


37.5 hrs 
2 hrs 


35 hrs 


‘Duration 


5 days 


1hr 


30 mins 


_ 30 mins 
:5 mins 
:1 day 


2 hrs 


1 day 


30 days 

10 days 

1 day 
30.27 days 


“ihr 


30 days. o 
0.13 days 


3 days 
299.9 days - 


ihr 
| ihr 
ihr 
“ihr 
“ihr 
.2 days 


1342.41 days 
1107.47 days 


_ 40 days 
_iday 


123 days 
5 days 


5 days 


5 days 


0.27 days 


5 days 


Predecessors 


Resource Names : | 
Business Analyst[27%], Corporate information Governance Leads 
CoA[2796], Developer 1[2796], Technology and Security SME 
AAHC[2796], Procurement CoA[2796], Program Manager[2796], Project 

:Manager[27%] 


169 Project Manager 


Business Analyst, Corporate Information Governance Leads CoA,Developer 

170 1,Technology and Security SME AAHC,Procurement CoA,Program 
Manager,Project Manager 

171 Procurement CoA,Project Manager 

172 Project Manager 

172 Procurement CoA[27%] | DDU 
Corporate Information Governance Leads CoA,Project Manager,Risk 
Privacy and Governance CoA | 
‘Corporate Information Governance Leads CoA[1396], Program 
'Manager[1326],Rìsk Privacy and Governance CoA[1396] | 

174 Procurement CoA[7%] | " 

177 Risk Privacy and Governance CoA[40%] 

172 Project Manager,Program Manager ž 


| 172 Project Manager, Risk Privacy and Governance CoA 


181 Risk Privacy and Governance CoA[0%] 
182 Risk Privacy and Governance CoA 


179 Project Manager[9394] 


Finance CoA 
186 Finance CoA 
177 Project Manager. 


. 188 Finance CoA 


189 Project Manager Žž — 
190 Procurement CoA[7%] 


191 Vendor 
194 Vendor 


. 195 Vendor 


Start Finish - 
Wed 20-08-26 Wed 20-09-02 
Wed 20-09-02 Wed 20-09-02 
Wed 20-09-02 Wed 20-09-02 
Wed 20-09-02 Wed 20-09-02 
"Wed 20-09-02 Wed 20-09-02 
Wed 20-09-02 Thu 20-09-03 
Wed 20-09-02 Wed 20-09-02 
Wed 20-09-02 Thu 20-09-03 
Thu 20-09-03 Thu 20-10-15 
Thu 20-10-15 Thu 20-10-29 
Wed 20-09-02 Thu 20-09-03 
Wed 20-09-02 Thu 20-10-15 
Wed 20-09-02 Wed 20-09-02 
"Wed 20-09-02 Wed 20-10-14 
Wed 20-10-14 Thu 20-10-15 
Thu 20-09-03 Wed 20-09-09 
Tue 19-09-03 Fri 20-10-16 
Tue 19-09-03 Tue 19-09-03 
Tue 19-09-03 Tue 19-09-03 
Thu 20-10-15 Thu 20-10-15 
Thu 20-10-15 Fri 20-10-16 
Fri 20-10-16 Fri 20-10-16 - 
Fri 20-10-16 Tue 20-10-20 
Mon 19-12-02 Wed 24-11-20 . 
Tue 20-10-20 Wed 24-11-20 
Tue 20-10-20 Fri 20-42-11 — 
Fri 20-12-11 Mon 20-12-14 
Mon 20-12-14 Wed 21-06-02 
Wed 21-06-02 Wed 21-06-09 _ 
Wed 21-06-09 Wed 21-06-16 - 
Wed 21-06-16 Tue 21-06-22 
Tue 21-06-22 Wed 21-06-23 
Wed 21-06-23 Tue 21-06-29 
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196 Vendor[93%] 
197 Vendor 
198 Vendor 
199 Vendor 
200 Vendor[93%] 
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WBS Task Name | Work 
4.1.9 BSA Stage 3 1hr 
4.110 Gap analysis 5 hrs 
4.1.11 UAT sign-off 2 hrs 
4.1.12 — Golive 14 hrs 
4.1.12.1 Go live plan | _7hrs 
4.1.12.2 Go-live plan approved | 1hr 
41.123. CAB Submission Preparation 3 hrs 
4.1.12.4 CAB Approval 2 hrs 
4.1.12.5 Launch solution 1 hr. | 
4.1.13 COS Dashboard V1 649 hrs © 
41131 .. Design . | 150 hrs 
4.1.13.2 Development/Configure 347 hrs 
4.1.13.3 Testing | 20 hrs 
4.1.13.4 Redevelopment for bug fixes 14 hrs 
4.1.13.5 Retesting 14 hrs 
4.1.13.6 Training - 14 hrs 
4.1.13.7 UAT sign-off 2 hrs 
4.1.13.8 Go Live 88 hrs 
4.1.13.8.1 Go live plan 7 hrs 
4.1.13.8.2 Go-live plan approved | 1hr 
4.1.13.8.3 _ CAB Submission Preparation 3 hrs 
4.1.13.8.4 CAB Approval Zhr 
4.1.13.8.5 Launch solution 1hr 
4.1.13.8.6 Communications and support _.75 hrs 
4.1.14 _COS Upgrades & Dashboard V2 569 hrs. 
41141 Design 150 hrs 
4.1.14.2 | Development/Configure 347 hrs 
4.1.14.3 Testing 14 hrs 
4.1.14.4 ` Redevelopment for bug fixes 14 hrs 
4.1.14.5 Retesting . A4hrs 
4.1.14.6 Training _.14 hrs 
4.1.14.7 UAT sign-off 2 hrs 
4.1.14.8 Go Live 14 hrs 
4.1.14.8.1 Go live plan 7 hrs 
41.14.82  . . Go-live plan approved. 1hr 
4.1.14.8.3 _ CAB Submission Preparation .3 hrs 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


Duration 


.1 day 
'1 day 


0.13 days 


5 days 
1 day 


1 day 


1 day 
1 day 


‘1 day 


101.77 days 
20 days | 
46.27 days 


:5 days 
5 days 
.5 days 
5 days 


“1 day 


44.5 days © 
:1 day 


1 day 
1 day 


0.5 days 


‘1 day 
10 days 
92.27 days 


20 days 


46.27 days 
5 days 
5 days 


:5 days 


5 days 
1 day 
5 days 
1 day 
1 day 
1 day 


Start 
Tue 21-06-29 


. Tue 21-06-29 


Tue 21-06-29 
Tue 21-06-29 


Tue 21-06-29 


Wed 21-06-30 
Fri 21-07-02 


Mon 21-07-05 


Tue 21-07-06 — 
Wed 21-07-07 
Wed 21-07-07, 


Tue 21-08-03 


Mon 21-10-04 


Tue 21-10-12 
Tue 21-10-19 
Mon 21-10-25 


Mon 21-11-01 


Tue 21-11-02 


Tue 21-11-02 
Wed 21-11-03 
Thu 21-11-04 


Fri 21-11-05 


Fri 21-11-05 
Mon 21-11-08 
Thu 22-07-21 


Thu 22-07-21 


|. Wed 22-08-17 


Tue 22-10-18 


Tue 22-10-25 


Tue 22-11-01 
Mon 22-11-07 


Tue 22-11-15 


Wed 22-11-16 
— Wed 22-11-16 


Thu 22-11-17 
Fri 22-11-18 


Finish 


Wed 21-06-30 


. Wed 21-06-30 


Tue 21-06-29 


Wed 21-06-30 


Fri 21-07-02 


'Mon 21-07-05 


Tue 21-07-06 


Wed 21-07-07 
Tue 21-11-23 


Predecessors 


Resource Names 
201 Vendor[13%] 


_ 201 Vendor[67%] 


Wed 21-07-07 | 


201 Technology and Security SME CoA,Technology and Security SME AAHC 


| 204 Vendor[93%] | 


Tue 21-08-03 — 


Mon 21-10-04 
Tue 21-10-12 
Tue 21-10-19 


“Mon 21-10-25 


Mon 21-11-01 
Tue 21-11-02 


Tue 21-11-23 
Wed 21-11-03 


‘Thu 21-11-04 


Fri 21-11-05 


Fri 21-11-05 


| Mon 21-11-08 
"Tue 21-11-23 
Wed 22-11-23 


‘Wed 22-08-17 


'Tue 22-10-18 


Tue 22-10-25 


Tue 22-11-01 


Mon 22-11-07 
Tue 22-11-15 


Wed 22-11-16 


Wed 22-11-23 
Thu 22-11-17 
Fri 22-11-18 


Mon 22-11-21 
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206 Vendor[13%] 

207 Vendor[40%] | | | | 
Technology and Security SME CoA[13%], Technology and Security SME 
AAHC 

209 Vendor[13%] 


208 


210 Vendor 


_ 212 Vendor 


213 Vendor(37*] _ 


214 Vendor[37%] 


215 Vendor[37%] 
216 Vendor[37%] | 
5,7? Technology and Security SME CoA[13%], Technology and Security SME 
: AAHC[13%] 

218 Vendor[93%] 

220 Vendor[1396] 

221 Vendor[40%] | +. 

222 Technology and Security SME CoA[1394], Technology and Security SME 

—“ AAHC[13%] 

223 Vendor[13%] 


224 Communications and Engagement Consultant - 


225FS+180 days Vendor 


227 Vendor 


_ 228 Vendor[37%] 
.229 Vendor[37%] 


230 Vendor[37%] 

231 Vendor[37%] n 

232 Technology and Security SME CoA[13%], Technology and Security SME 
: AAHC[1396] 

233 Vendor[93*t] 

235 Vendor[13%] 


. 236 Vendor[40%] 
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WBS 


4.1.14.8.4 


4.1.14.8.5 
4.1.15 


4.1.15.1 
4.1.15.2 


41153 


4.1.15.4 
4.1.15.5 
4145.6 


4.1.15.7 


4.1.15.8 

4.1.15.8.1 
4.1.15.8.2 
4.1.15.8.3 


4.1.15.8.4 


4.1.15.8.5 
4.1.16 


4.1.16.1 


4.1.16.2 
4.1.16.3 
4.1.16.4 
4.1.16.5 
:4.1.16.6 


4.1.16.7 


4.1.16.8 

4.1.16.8.1 
4.1.16.8.2 
4.1.16.8.3 


4.1.16.8.4 


4.1.16.8.5 
4.2 

4.2.1 
4.2.2 
4.2.3 
424. 


Task Name 


CAB Approval 


Launch solution _ MM 
COS Upgrades & Dashboard V3 


Design 


Developm ent/Configu re 
Testing 

Redevelopment for bug fixes 
Retesting 

Training 


UAT sign-off 


Go Live — 
Go live plan © 
Go-live plan approved | 
CAB Submission Preparation 
CAB Approval 


Launch solution 


| cos Upgrades & Dashboard V4 - 


Design 


Development/Configure 
Testing | 
Redevelopment for bug fixes 
Retesting 

_ Training 


UAT sign-off 
Go Live o 
_Go live plan 
Go-live plan approved 
CAB Submission Preparation 


CAB Approval 


Launch solution _ | 
Not For Profit Organizations added to Business Directory 
Determine Reguirements 
Configure City View 
Testing — | 
Redevelopment for bug fixes 
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/ Work 


2hrs 


hr u 
568 hrs 


150 hrs 


347 hrs 
14 hrs 
14 hrs 
14 hrs 
14 hrs 


1hr 


14 hrs 
7 hrs 
1hr 


:3 hrs 
2 hrs 


1hr 
_ 569 hrs 


150 hrs 


347 hrs 
14 hrs 
14 hrs 
14 hrs 


14 hrs 


2 hrs 


14 hrs 
7 hrs | 


EL 


3hrs 
2 hrs 
1 hr 
53 hrs 
4 hrs 


20 hrs 
5 hrs 


10 hrs À 


Duration 


1 day 


1 day 
91.77 days 


20 days 


f 46.27 days 


5 days 


'5 days 
5 days 
.5 days 


0.5 days 


5 days 
1 day 
1 day 
1 day 


‘1 day 


1 day 
92.27 days 


20 days 
46.27 days 


:5 days 


5 days 
5 days 


5.5 days 
d day 


5 days 


‘1 day 


1 day 
1 day 


1 day 


1 day 
15 days 
2 days 
5 days 
2 days 
5 days 


Start Finish 
Mon 22-11-21 Tue 22-11-22 
Tue22-11-22 Wed 22-11-23 
Thu 23-07-20 Mon 23-11-20 
Thu 23-07-20 Tue 23-08-15 
Tue 23-08-15 Tue 23-10-17 _ 
“Tue 23-10-17 Mon 23-10-23 
Mon 23-10-23 Mon 23-10-30 
Mon 23-10-30 Mon 23-11-06 
Mon 23-11-06 Fri 23-11-10 
Fri23-11-10 Mon 23-11-13 
Mon 23-11-13 Mon 23-11-20 
Mon 23-11-13 Tue 23-11-14 
Tue 23-11-14 Wed 23-11-15 
Wed 23-11-15 Thu 23-11-16 
Thu 23-11-16 -Fri 23-11-17 
Fri 23-11-17 Mon 23-11-20 
Thu 24-07-18 Wed 24-11-20 
Thu 24-07-18 Wed 24-08-14 
Wed 24-08-14 Tue 24-10-15 
Tue 24-10-15 — Tue 24-10-22 
Tue 24-10-22 Tue 24-10-29 
Tue 24-10-29 Mon 24-11-04 
‘Mon 24-11-04 Tue 24-11-12 
Tue 24-11-12 Wed 24-11-13 
Wed 24-11-13 Wed 24-11-20 
‘Wed 24-11-13 Thu 24-11-14 
Thu 24-11-14 Fri 24-11-15 
Fri24-11-15 Mon 24-11-18 
Mon 24-11-18 Tue 24-11-19 
Tue 24-11-19 Wed 24-11-20 
Mon 19-12-02 Fri 19-12-20 
Mon 19-12-02 Wed 19-12-04 
Wed 19-12-04 Wed 19-12-11 
Wed 19-12-11 Fri 19-12-13 
Fri19-12-13 Thu 19-12-19 
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. 242 Vendor[3 


Resource Names ` 

Technology and Security SME CoA[13%], Technology and Security SME 
= AAHC[13*6]  _ 

238 Vendor[13%] 


237 


239FS+180 days Vendor 


241 Vendor — 
[3776] 
243. Vendor[3796] 
[ 


244 Vendor[37%] 

245 Vendor[37%] | | 
Technology and Security SME CoA[1396], Technology and Security SME 
AAHC[13%] 


247 Vendor[93%] 
249 Vendor[13?6] 


250 Vendor[4096] | m | 
Technology and Security SME CoA[13%], Technology and Security SME 


251 
^ AAHC[1399] 


252 Vendor[13%] 


253FS+180 days | Vendor 


255 Vendor _ 

256 Vendor[37%] 

257 Vendor[3794] 

258 Vendor[37%] 

259 Vendor[37%] | | | 
Technology and Security SME CoA[13%], Technology and Security SME 


260 
AAHC[13%] 


261 Vendor[93%] —— 
263 Vendor[13%] - 
.. 264 Vendor[4096] 


Technology and Security SME CoA[13%], Technology and Security SME 
:AAHC[1392] 
266 Vendor{13%] 


265 


56 Application Support CoA[272e] 


| 269 Application Support CoA[27%] 


270 Technology and Security SME CoA 


_ 271 Application Support CoA[27%] 
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WBS 
425 
4.2.6 
4.2.7 
4.2.8 
4.2.8.1 
4.2.8.2 
4.2.8.3 
4.2.8.4 
4.2.8.5 
4.3 
431 
4.3.2 
4.3.3 
43.4 
4.3.5 
4.3.6 
4.3.7 
4.3.8 
4.3.8.1 
4.3.8.2 
4.3.8.3 
| 43.8.4 
4.3.8.5 
44. 
44.1 
442. 
443. 
AAA 
4.4.5 
4.4.6 
4.4.7 
4.4.8 
4.4.8.1 
4.4.8.2 
4.4.8.3 
4.4.8.4 
4.4.8.5 
4.5 
4.5.1 
4.5.2 
4.5.3 
4.5.4 
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Task Name 


Retesting 
Training 


_ UAT sign-off | 


Go Live A 
Go live plan | 
Go-live plan approved o 
CAB Submission Preparation 
CAB Approval 
Launch solution 


| | Census API 


Design l 
Development/Configure 
Testing 
redevelopment for bug fixes 


| _Retesting 


Training 
UAT sign-off 
Go Live 
Go live plan 
Go-live plan approved 
CAB Submission Preparation 
CAB Approval _ 
Launch solution 


Recreation Center Platform API 


Design — Pr 
Development/Configure 


__ Testing 


Redevelopment for bug fixes 
Retesting 


Training 
_ UAT sign-off 


Go Live 
Go live plan 
Go-live plan approved 


CAB Submission Preparation | 


CAB Approval 
Launch solution 


| | Wearables API 


Design 
Development/Configure 
Testing u 
Redevelopment for bug fixes 


à l'information 


Work 


_ 5 hrs 
_.3 hrs 


1hr 


'5hrs. 


1 hr 
1hr 
1hr 


Ahr 


1hr 
99 hrs 


10 hrs u 
50 hrs 


5 hrs 
15 hrs 
5 hrs 
5 hrs 


ihr 


8 hrs | 


2hrs 
ihr 
_ 3hrs 


1 hr 
1 hr 
99 hrs 


10 hrs 


50 hrs 
5 hrs 
15 hrs 


5 hrs 


5 hrs 


1hr 
8hrs 
2 hrs 
‘Thr 
3 hrs 


1hr 


11 hr 


101 hrs 
10 hrs 


50 hrs | 


5hrs. 
T5 hrs 


Duration 


1 day 


1 day mE 


1 day 


_ 3.27 days 


1 day 


0.13 days 


1 day — 


0.13 days 


1 day 
36 days 


_2days — 


20 days 


_iday 
5 days 


1 day 
1 day 


1day | 


5 days 
1 day 

1 day 
1day 
1day 


‘1 day 


34 days 


2days — 


18 days 


1 day 


5 days 
1 day 


.1 day 
‘1 day 
> days 


1 day 
1 day 
1 day 
1 day 
1 day 


| 34 days 


2 days 
18 days 
1 day 


'5days | 


Start 
Thu 19-12-19 


. FAAS-12-13 


Mon 19-12-16 


. Tue 19-12-17 
Tue 19-12-17 
Wed 19-12-18 


Wed 19-12-18 
Thu 19-12-19 


Thu 19-12-19 - 


Thu 21-03-11 
Thu 21-03-11 


‘Mon 21-03-15 


Tue 21-04-13 


' Wed 21-04-14 


Tue 21-04-20 
Wed 21-04-21 


Thu 21-04-22 
Fri 21-04-23 
. Fri 21-04-23 


Mon 21-04-26 


Tue 21-04-27 
Wed 21-04-28 
Thu 21-04-29 


Mon 21-03-15 
Mon 21-03-15 
Wed 21-03-17 


Tue 21-04-13 
Wed 21-04-14 
Tue 21-04-20 — 
Wed 21-04-21 


Thu 21-04-22 
Fri 21-04-23 
Fri 21-04-23 
Mon 21-04-26 
Tue 21-04-27 
Wed 21-04-28 


Thu 21-04-29 

‘Mon 21-03-15 
Mon 21-03-15 
-Wed 21-03-17 


Tue 21-04-13 
Wed 21-04-14 
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Finish 


_ Fri 19-12-20 - 


Mon 19-12-16 
Tue 19-12-17 
Fri 19-12-20 


Wed 19-12-18 
‘Wed 19-12-18 . 
Thu19-12-19 .— 
Thu 19-12-19 | 

‘Fri 19-12-20 


Fri 21-04-30 


jM 
Tue 21-04-13  . 
Wed 21-04-14 


Tue 21-04-20 
Wed 21-04-21 


Thu 21-04-22 


Fri 21-04-23 
Fri 21-04-30 
Mon 21-04-26 
Tue 21-04-27 
Wed 21-04-28 
Thu 21-04-29 
Fri 21-04-30 - 
Fri 21-04-30 


| Wed 21-03-17 


Tue 21-04-13 


‘Wed 21-04-14 


Tue 21-04-20 


Wed 21-04-21 
Thu 21-04-22  — 
‘Fri 21-04-23 
‘Fri 21-04-30 
‘Mon 21-04-26 


Tue 21-04-27 
Wed 21-04-28 
Thu 21-04-29 
Fri 21-04-30 
Fri 21-04-30 


Wed 21-03-17 - 


Tue 21-04-13 
Wed 21-04-14 
Tue 21-04-20 


Predecessors 


Resource Names 


272 Technology and Security SME CoA[6796] 


271 Application Support CoA 
274 Application Support CoA 


275 Application Support CoA[93%] | 


277 Technology and Security SME CoA 
278 Application Support CoA[93%] 
279 Technology and Security SME CoA 
280 Application Support CoA[93%] 


196FS-60 days ^ Developer CoA[67%] - 


283 Developer CoA[27%] 
284 Application Support CoA[67%] 
285 Developer CoA[4096] 


. 286 Application Support CoA[6790] 


287 Developer CoA[67%] 
288 Developer CoA[13?6] 


289 Developer CoA[27%] 
291 Technology and Security SME CoA 
292 Developer CoA[40%] 


.293 Technology and Security SME CoA | 


294 Developer CoA[13%] 


283 Application Support CoA[67%], Vendor 


297 Vendor[37%] 
298 Application Support CoA[67%] 
299 Vendor[40%] 


. 300 Application Support CoA[67%] 


307 Technology and Security SME CoA[13%], Vendor[13%] 


301 Vendor[67%] 
302 Vendor[13%] 


303 Vendor[27%] 


305 Vendor[13%], Technology and Security SME CoA 


306 Vendor[40%] 


__ 308 Vendor[13%] 


| 283 Vendor[6796] 


311 Vendor[37%] 


312 Vendor[67%] 
..313 Vendor[40%] 
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WBS Task Name Work Duration Start Finish Predecessors Resource Names 
4.5.5 | Retesting 5 hrs 1day | ‘Tue 21-04-20 Wed 21-04-21 314 Vendor[67%] 
4.5.6 Training <5 hrs 1 day Wed 21-04-21 Thu 21-04-22 315 Vendor[67%] — u P l | 
457 UAT sign-off 2 hrs aay Thu 21-04-22 Fri 21-04-23 316 Technology and Security SME CoA[13%], Technology and Security SME 
| | a an AAHC[13%] 
4.5.8 Go Live | 9hrs 5 days _ Fri 21-04-23 Fri 21-04-30 
4.5.8.1 Go live plan 2 hrs 1 day Fri 21-04-23 :Mon 21-04-26 317 Vendor[27*6] 
4.5.8.2 Go-live plan approved | 1hr 1 day Mon 21-04-26 Tue 21-04-27 .... 319 Vendor[13%] 
4.5.8.3 CAB Submission Preparation 3 hrs iday Tue 21-04-27 Wed 21-04-28 | _ 320 Vendor[40%] | 
FE CAB Approval “HE day Wed 21-04-28 ‘Thu 21-04-29 321 Technology and Security SME CoA[13%], Technology and Security SME 
ie | | AAHC[13%] 
4.5.8.5 Launch solution 1 hr 1day Thu21-04-29 X Fri 21-04-30 322 Vendor[13%] _ 
4.6 GIS Data API 101 hrs 34 days Fri 21-04-30 Wed 21-06-16 | 
4.6.1 . Design g | 10 hrs 2 days Fri 21-04-30 =: Tue 21-05-04 © _ 323 GIS Personnel CoA[67%] 
4.6.2 Development/Configure :50 hrs 18 days Tue 21-05-04 Fri 21-05-28 _ 325 Vendor[37%] 
46.3 — Testing | 5 hrs 1 day Fri 21-05-28 Fri 21-05-28 — .326 GIS Personnel CoA[67%] 
4.6.4. . Redevelopment for bug fixes 15 hrs 5 days Fri 21-05-28 Fri 21-06-04 — 327 Vendor[40%] 
465 _ Retesting 5 hrs 1day Fri 21-06-04 Mon 21-06-07 328 Vendor[67%] 
4.6.6. Training 5 hrs 1 day Mon 21-06-07 . Tue 21-06-08 329 Vendor[67%] — NEM E : 
467 UAT sign-off 3 1 day Tue 21-06-08 Wed 21-06-09 330 Technology and Security SME CoA[13%],Technology and Security SME 
Cn | | AAHC[13%] 
4.6.8 Go Live 9 hrs 5 days Wed 21-06-09 Wed 21-06-16 
4.6.8.1 Go live plan ‘2 hrs 1day | Wed 21-06-09 Thu 21-06-10 .331 Vendor[27%] _ 
4.6.82 — Go-live plan approved. 1hr 1 day Thu 21-06-10 ‘Fri 21-06-11 — 333 Vendor[13%] _ 
4.6.8.3 . CAB Submission Preparation 3 hrs 1 day Fri 21-06-11 Mon 21-06-14 334 Vendor[4096] 7 WN a = 
Leas CAB Approval > hrs idis Mon 21-06-14 Tue 21-06-15 Technology and Security SME CoA[1396], Technology and Security SME 
| M AAHC[13%] 
4.6.8.5 Launch solution _ 1 hr 1 day _ Tue 21-06-15 ¿Wed 21-06-16 _ 336 Vendor[13%] 
47 Social Media API 101 hrs 34 days Wed 21-06-16 Mon 21-08-02 | ne | 
471 Design . | 10 hrs :2 days Wed 21-06-16 Fri 21-06-18 337 Vendor[6796] 
47.2. Development/Configure S0hrs . 18 days Fri 21-06-18 Tue 21-07-13 339 Vendor[37?6] 
4.7.3 Testing 5 hrs 1 day Tue 21-07-13 Wed 21-07-14 340 Vendor[67%] 
4.7.4 Redevelopment for bug fixes 15 hrs :5 days Wed 21-07-14 Wed 21-07-21 341 Vendor[40%] | 
4.7.5 Retesting 5 hrs 1 day Wed 21-07-21 Thu 21-07-22 342 Vendor[67%] 
4.7.6 Training 5 hrs 1 day Thu 21-07-22 Fri 21-07-23 _ 343 Vendor[67%] | | | 
477 UAT sign-off 2 hrs ids Fri 21-07-23 Mon 21-07-26 344 Technology and Security SME CoA[13%], Technology and Security SME 
| | AAHC[13%] 
4.7.8 Go Live 9 hrs 5 days Mon 21-07-26 Mon 21-08-02 MAN 
4.7.8.1 Go live plan 2 hrs 1 day Mon 21-07-26 Tue 21-07-27 .345 Vendor[27%] 
4.7.8.2 Go-live plan approved | 1hr. 1 day Tue 21-07-27 _ Wed 21-07-28 347 Vendor[13%] _ 
4.7.8.3 CAB Submission Preparation _ 3 hrs 1 day Wed 21-07-28 Thu 21-07-29 348 Vendor[40%] | | 
4784 CAB Approval hs id Thy 21-07-29 Fri 21-07-30 349 Technology and Security SME CoA[13%],Technology and Security SME 
a | | | | | porn AAHC[1396] | 
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Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


WBS ^ . Task Name 

4.7.8.5 — .. Launch solution | pr 

4.8 Local, Provincial & Federal Open Data Platforms API 
4.8.1 Development/Configure 

4.8.2 | Testing 

4.8.3 .. Redevelopment for bug fixes 

4.8.4 ___Retesting 

4.8.5 : Training 

4.8.6 UAT sign-off 

4.8.7 |^ Golive 

4.8.7.1 . Go live plan 

4.8.7.2 | Go-live plan approved 

4.8.7.3 | .... CAB Submission Preparation 

4.8.7.4 CAB Approval 

4.8.7.5 | | PS Launch solution 

4.9  _ _: Service Inventory MET 

4.9.1. | Phase 2 Engagement and Communications 

4.9.1.1 Communications and promotions 

4.9.1.2 Workshops for service providers 

4.9.1.3 | . Interviews with service providers 

4.9.1.4 Pop-ups. 

4.9.1.5 | Online Tool 

49.16 . Kiosks wre 

4.91.7 ___ Phase 2 What we Heard report 

4.9.2 Service Inventory planning and consultation 

493 Service Inventory V1 & API 

4.9.3.1 Planning & Consultation, gathering requirements and data 
4.9.3.2 | | Build service inventory V1 | mE 
4.9.3.3 Build API & Connect to COS 

4.9.4 Service Inventory V2 & API 

4.9.4.1 Planning & Consultation, gathering requirements and data 
4.9.4.2 Build service inventory V2 

4.9.4.3 Build API & Connect to COS 

4.9.5 Service Inventory V3 & API 

4.9.5.1 Planning & Consultation, gathering requirements and data 
4.9.5.2 l | Build service inventory V3 | 

49.5.3 | Build API & Connect to COS 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


Work 

1 hr 
721 hrs 
600 hrs 


35 hrs 


20hrs | 
20 hrs 
35 hrs 


2 hrs 
9 hrs 


2hrs 


1hr 


3 hrs 


2 hrs 


| 1 hr WN 
8,320 hrs 


220 hrs 
56 hrs 


“A4 hrs 
16hrs — 


42 hrs 
34 hrs 
8 hrs 

20 hrs 


200 hrs 


| 2,050 hrs 


450 hrs 


| 900 hrs 
700 hrs 
2,050 hrs 


450 hrs 


900 hrs 
700 hrs 


_ 1,750 hrs 


450 hrs 


600 hrs 
700 hrs 


Duration | 
:1day Žž 
126 days 


100 days 
5 days 
5 days 


:5 days | 


5 days 


1 day 


:5 days 
‘1 day 
1 day 
,1 day 


:1 day 


1day 
790 days 
39 days 


10 days 
10 days 


.4 days 
6 days 
5 days 
1 day | 
3 days | 
:20 days 


; 200 days 


40 days 


60 days 


:100 days 


200 days 
40 days 


:60 days. 


100 days 
180 days 


40 days 


40 days | 


100 days 


| Start | 
..Fri 21-07-30 — 


Mon 21-08-02 


Tue 21-12-14 


| Tue 21-12-21 


Thu 21-12-30 


Wed 22-01-05 
Wed 22-01-12 
Thu 22-01-13 


Thu 22-01-13. 
Fri 22-01-14 
Mon 22-01-17 


Tue 22-01-18 


Wed 22-01-19 
Thu 20-04-16 


Thu 20-04-16 
Thu 20-04-16 
Wed 20-04-29 
Wed 20-05-13 


Tue 20-05-19 
‘Wed 20-05-27 


Wed 20-06-03 


— Thu 20-06-04 
Mon 20-06-08 


Wed 20-04-29 


Wed 20-04-29 


Tue 20-06-23 
Fri 20-09-11 
Thu 21-01-28 


Thu 21-01-28 


Tue 21-03-23 


Tue 21-06-15 


. Wed 21-10-27 
Wed 21-10-27 


Tue 21-12-21 


Mon 22-02-14 
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Finish 
Mon 21-08-02 
Thu 22-01-20 


Tue 21-12-14 


Tue 21-12-21 


: Thu 21-12-30 
' Wed 22-01-05 
‘Wed 22-01-12 


Thu 22-01-13 


Thu 22-01-20 
Fri 22-01-14. 
Mon 22-01-17 
Tue 22-01-18 


Wed 22-01-19 


Thu 22-01-20 
Thu 23-03-23 


‘Mon 20-06-08 


Wed 20-04-29 
Wed 20-05-13 
Tue 20-05-19 

Wed 20-05-27 
Wed 20-06-03 
Thu 20-06-04 

Mon 20-06-08 


Mon 20-07-06 


Thu 21-01-28 


Tue 20-06-23 


Fri 20-09-11 
Thu 21-01-28 
Wed 21-10-27 


Tue 21-03-23 


Tue 21-06-15 
Wed 21-10-27 
Mon 22-06-27 


Tue 21-12-21 


Mon 22-02-14 ` 
Mon 22-06-27 


Predecessors Resource Names 


350 Vendor[13%] 


351 Vendor[80%] _ 
353 Vendor[93%] _ 


354 Vendor[53%] 


355 Vendor[53%] 
356 Vendor[93%] 


Technology and Security SME CoA[1394], Technology and Secu rity SME 


357 
AAHC[13%] 


358 Vendor[279] 
360 Vendor[1394] 


361 Vendor[40?0] 


362 
AAHC[1394] 


363 Vendor[13%] 


| 85 Communications and Engagement Consultant 


367 Communications and Engagement Consultant 
368 Communications and Engagement Consultant 
369 Communications and Engagement Consultant 
370 Communications and Engagement Consultant 
371 Communications and Engagement Consultant 
372. Communications and Engagement Consultant 


373 
~ 2[5794] 


Technology and Security SME CoA[13%], Technology and Security SME - 


Business Analyst[57%], Data Analyst[57%], Developer 1[57%], Developer 


Business Analyst[67%], Data Analyst[67%], Developer 1[67%], Developer 


7 
i :2[67%] 


376 Data Analyst[67%], Developer 1[67%], Developer 2[67%] 
377 Vendor 


Business Analyst[6796],Data Analyst[67%], Developer 1[67%], Developer 


378 
2[67%] 


380 Data Analyst[67%], Developer 1[67%], Developer 2[67%] - 


381 Vendor 


Business Analyst[6796],Data Analyst[67%], Developer 1[67%], Developer | 


2 
382 [5795] 


| _384 Data Analyst[67%], Developer 1[67%],Developer 2[6796] 


385 Vendor 
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WBS 
4.9.6 
4.9.6.1 


4.9.6.2 
A1 
4.10.1 
4.10.2 
4.11 
4111 
A112. 
4.12 
A121 
42.2 
4.13 
4.13.1 
4.13.2 
4.14 
4.14.1 
414.2. 
415 — 
4.15.1 
4.15.1.1 
4.15.1.2 
4.15.1.3 
4.15.14 
4.15.1.5 
4.15.1.6 
4.15.2 
4.15.2.1 
4152.11. 
4.15.2.1.2 


415.213 _ 


4.15.2.1.4 
4.15.2.1.5 
4.15.2.1.6. 
4.15.2.1.7 
4.15.2.1.8 
4.15.2.1.9 


4152193 — 
4152192 | 


-Task Name | 
Service Inventory V4 & API 


Planning & Consultation, gathering requirements and data 


Build service inventory V4 

. Build API & Connect to COS " 
eMental Health COS APIs & Dashboard 

Gather requirements & data 

Build COS APIs & dashboard 
Well-Being Tool COS APIs & Dashboard 

Gather requirements & data 

Build COS APIs & dashboard . 
People Like Me COS APIs & Dashboard 

Gather requirements & data 

Build COS APIs & dashboard 


Engagement for Community Involvement COS APIs & Dashboard 


Gather requirements & data 
Build COS APIs & dashboard | 
Clinical Systems COS APIs & Dashboard 
Gather reguirements & data 
Build COS APIs & dashboard 
Accessibility and Usability 
. Phase 3 Communications and Engagement 
Communications and promotions 
Workshops for service providers 
Pop-ups | | i 
_ Online Tool 
Kiosks 
Phase 3 What we Heard report 
Web Interface 
MyAirdrie Interface 
Design . 
Update PIA | 
Development/Configure 
Testing E | 
Redevelopment for bug fixes 
.. Retesting 
Training 
UAT sign-off 
Go Live 
Go live plan 
Go-live plan approved. 
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Processed under the provisions of the Access to 
Information Act /Rêvisê en vertu de la Loi sur l'accês 
a l'information 


Work | 
2,050 hrs 


450 hrs 


900 hrs 
700 hrs 


375 hrs 


187.5 hrs 


‘187.5 hrs 


375 hrs 


187.5 hrs — 
187.5 hrs — 


375 hrs 
187.5 hrs 
187.5 hrs 


375 hrs 


187.5 hrs 


187.5 hrs 
375 hrs 
187.5 hrs 


187.5 hrs 


9,258 hrs 


‘210 hrs 


56 hrs 


:50 hrs 


A2 hrs | 
34 hrs 
8 hrs 
20 hrs 
956 hrs 
221 hrs 
75 hrs 
2 hrs 


75 hrs 


20 hrs 


‘20 hrs 


10 hrs 
10 hrs 
1 hr 
8 hrs 


:2 hrs 


1hr 


| Duration 
:200 days 


40 days 


60 days 
100 days _ 
50 days _ 
:25 days 
'25 days 


50 days 


:25 days 


25 days 


.50 days 


25 days 


_ 25 days 
:50 days 


25 days 
:25 days 
50 days 
-25 days 
.25 days 


1058 days 


:36 days 
10 days 


10 days 


:6 days 
:5 days 


2 days 
3 days 


:813 days 


56 days 
15 days 


1 day 


15 days 
5 days 


5 days 


5 days 
5 days. 
1 day 
5 days 


.1 day 


1 day 


Start 
Mon 22-06-27 


‘Mon 22-06-27 


Fri 22-08-19 - 


Tue 22-11-08 
Thu 21-01-28 


— Thu 21-01-28 
Wed 21-03-03 


Tue 21-06-29 


Tue 21-06-29 
Tue 21-08-03 - 


Fri 21-09-03 


Fri 21-09-03 .— 
Fri 21-10-08 - 


Wed 22-11-23 


| Wed 22-11-23 


Tue 22-22-27 | 
Mon 23-01-30 
Mon 23-01-30 
Fri 23-03-03 

Mon 20-12-14 
Mon 20-12-14 


‘Mon 20-12-14 


Tue 20-12-29 
Wed 21-01-13 


Wed 21-01-20 
Wed 21-01-27 
Fri 21-01-29 

Mon 20-12-14 


Mon 20-12-14 
Mon 20-12-14 


— Wed 21-01-06 
Wed 21-01-06 - 


Tue 21-01-26 
Tue 21-02-02 
Mon 21-02-08 
Tue 21-02-16 


Tue 21-02-23 
Wed 21-02-24 


Wed 21-02-24 
Thu 21-02-25 
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Finish 


Thu 23-03-23 


Fri 22-08-19 


Tue 22-11-08 - 


Thu 23-03-23 
Thu 21-04-08 
Wed 21-03-03 
Thu 21-04-08 


_ Fri 21-09-03 
Tue 21-08-03 


Fri 21-09-03 


Fri 21-11-12 


Fri 21-10-08 
Fri 21-11-12 - 


Mon 23-01-30 


Tue 22-12-27 


Predecessors 


Resource Names 


386 
2[6796] 


388 Data Analyst[67%],Developer 1[67%], Developer 2[67%] 


_389 Vendor 


378 Vendor 
392 Vendor 


204 Vendor 
395 Vendor 


UN 
_398 Vendor 


| | 239 Vendor 


Mon 23-01-30 


Thu 23-04-06 
Fri 23-03-03 


Thu 23-04-06 


Thu 24-11-07 


Wed 21-02-03 


Tue 20-12-29 


Wed 21-01-13 


Wed 21-01-20 
Wed 21-01-27 
Fri 21-01-29 
Wed 21-02-03 
Wed 23-12-13 
Tue 21-03-02 


Wed 21-01-06 


Thu 21-01-07 
Tue 21-01-26 
Tue 21-02-02 
Mon 21-02-08 
Tue 21-02-16 


Tue 21-02-23 


Wed 21-02-24 
Tue 21-03-02 


Thu 21-02-25 


Fri 21-02-26 


401 Vendor 


402 Vendor 
404. Vendor 


| 195 Communications and Engagement Consultant 
. 408 Communications and Engagement Consultant 


409 Communications and Engagement Consultant 
410 Communications and Engagement Consultant 
411 Communications and Engagement Consultant 
412 Communications and Engagement Consultant 


| 195 Developer CoA[6794] 


__416 Risk Privacy and Governance CoA, Project Manager — 


416 Developer CoA[67%] 
418 Application Support CoA[53%] 
419 Developer CoA[53%] 
420 Application Support CoA[27%] 
421 Developer CoA[27%] 
422 Developer CoA[13%] 


| 423 Develo per CoA 


425.Technology and Security SME CoA 


“Business Analyst[6796],Data Analyst[67%], Developer 1[67%], Developer 
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WBS 


4.15.2.1.9.3 
4.15.2194 
4.15.21.9.5 | 


4.15.2.2 

4.15.2.2.1 
4.15.2.2.2 
4.15.2.2.3 
4.15.2.2.4 
4.15.2.2.5 
4.15.2.2.6 
4.15.2.2.7 
4.15.2.2.8 


415.222.8.3 


4.15.2.2.8.2 


4152283 


4.15.2.2.8.4 
4.15.2.2.8.5 
4.15.2.3 
4.15.2.3.1 
4.15.2.3.2 
4.15.2.3.3 
4.15.2.3.4 
4.15.2.3.5 
4.15.2.3.6 
4.15.2.3.7. 
415.238 
4.15.2.3.8.1 


4.15.2.3.8.2 | 


4.15.2.3.8.3 
4.15.2.3.8.4 


4.15.2.3.8.5 . 


4.15.2.4 
4.15.2.4.1 


4.15.2.4.2 
4.15.2.4.3 
4.15.2.4.4 
4.15.2.4.5 
4.15.2.4.6 
4.15.2.4.7 
4.15.2.4.8 


4.15.2.4.8.1 : 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Rêvisê en vertu de la Loi sur l'accês 
a l'information 


Task Name EET 
CAB Submission Preparation 


CAB Approval 
Launch solution 


— MyAirdrie User Authentication — 


Design 
Development/Configure 
Testing | 
Redevelopment for bug fixes 
Retesting 
Training — 
UAT sign-off 
Go Live _ 
Go live plan | 
Go-live plan approved - 
CAB Submission Preparation 
CAB Approval 
Launch solution 


MyAirdrie Portal Integration 


Design 
Development/Configure _ 
Testing 


| Redevelopment for bug fixes 


Retesting 
Training 
UAT sign-off 


.Go Live 


. Go live plan | 
Go-live plan approved 


CAB Submission Preparation 


CAB Approval 
Launch solution 


Portal Updates 


Design 


Development/Configu re 


Testing 

Redevelopment for bug fixes 
Retesting 

Training 


_ UAT sign-off 


Go Live 
Go live plan 


"Work 
3hrs 
:1hr 


Thr — 
219 hrs 
75 hrs 
75 hrs 
20 hrs 
20 hrs 
10 hrs 
10 hrs 
1hr 
8hrs. 
2 hrs 


‘Thr 


3 hrs 


1hr 


1hr 
219 hrs 
75 hrs 
75 hrs 
20 hrs 
20 hrs 
10 hrs 
10 hrs 
1 hr 


8 hrs 


2 hrs 
1 hr 
3 hrs 


‘hr 


1hr 
99 hrs 


20 hrs 


40 hrs 
10 hrs 
10 hrs 
5 hrs 


:5 hrs 
‘Thr 
8 hrs 
'2 hrs 


Duration 
1 day 

1 day 
1day - 
56 days 
15 days 
15 days 
5 days 
5 days 
5 days 
5 days 


| E day 
.5 days 
1 day 
.i day 
.1day 


1 day 


'1 day 


56 days 


..15 days. 


15 days. 


5 days 


5 days 
5 days 
5 days 


1 day 
5 days 
.1 day 
1 day 
:1 day 


1 day 


1day | 
35 days 


5 days 


: 10 days 


5 days 
5 days 


:2 days 
.:2 days 
.1 day 
:5 days 
1 day 


> Start Finish > 
Fri 21-02-26 Mon 21-03-01 
Mon 21-03-01 Tue 21-03-02 
Tue 21-03-02 Tue 21-03-02 
Tue 21-03-02 Tue 21-05-18 
Tue 21-03-02 Tue 21-03-23 
Tue 21-03-23 Wed 21-04-14 
Wed 21-04-14 Tue 21-04-20 
Tue 21-04-20 Tue 21-04-27 
Tue 21-04-27 Tue 21-05-04 
Tue 21-05-04 Mon 21-05-10 
Mon 21-05-10 Tue 21-05-11 
Tue 21-05-11 Tue 21-05-18 
Tue 21-05-11 Wed21-05-12 __ 
Wed 21-05-12 Thu 21-05-13 __ 
Thu 21-05-13 Fri 21-05-14 
Fri21-05-14 Mon 21-05-17 
Mon 21-05-17 Tue 21-05-18 
Tue 21-05-18 Mon 21-08-02 
‘Tue 21-05-18 Tue 21-06-08 
Tue 21-06-08 Mon 21-06-28 
Mon 21-06-28 Tue 21-07-06 
Tue 21-07-06 Mon 21-07-12 
‘Mon 21-07-12 Mon 21-07-19 
‘Mon 21-07-19 Mon 21-07-26 
Mon 21-07-26 Tue 21-07-27 
Tue 21-07-27 Mon 21-08-02 . — 
Tue 21-07-27 Wed 21-07-28 
Wed 21-07-28 Thu 21-07-29 
Thu 21-07-29  Fri21-07-30 - 
Fri 21-07-30 Mon 21-08-02 
Mon 21-08-02 Mon 21-08-02 
Mon 22-04-04 Thu 22-05-19 
Mon 22-04-04 Mon 22-04-11 
Mon 22-04-11 Fri 22-04-22 
Fri22-04-22 Fri 22-04-29 
Fri 22-04-29 Fri 22-05-06 
Fri 22-05-06 Tue 22-05-10 
Tue 22-05-10 ¿Wed 22-05-11 : 
Wed 22-05-11 Thu 22-05-12 | 
= Thu 22-05-12 Thu 22-05-19 © 
Thu 22-05-12 Fri 22-05-13 
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Predecessors Resource Names 


426 Developer CoA . | 
427 Technology and Security SME CoA 
428 Developer CoA 


429 Developer CoA[67%] 
431 Developer CoA[67%] 
432 Application Support CoA[53%] 
433 Developer CoA[53%] 
434 Application Support CoA[27%] 
435 Developer CoA[27%] 
436 Developer CoA[1396] 


437. Developer CoA - 


439 Technology and Security SME CoA . 


440 Developer CoA 


.. 441 Technology and Security SME CoA 


442 Developer CoA 


443 Developer CoA[67%] 
445 Developer CoA[67%] — — 
446 Application Support CoA[S3%] 


447 Developer CoA[53%] 


448 Application Support CoA[27%] 


_ 449 Developer CoA[27%] 


450 Developer CoA[13%] 


451 Developer CoA 

453 Technology and Security SME CoA 
454 Developer CoA g 
455 Technology and Security SME CoA 
456 Developer CoA 


457FS+180 days Developer CoA[5396] 


459 Developer CoA[53%] 
460 Application Support CoA[27%] 


_ 461 Developer CoA[27%] 


462 Application Support CoA[33%] 
463 Developer CoA[33%] 
464 Developer CoA[13%] _ 


465 Developer CoA 
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WBS — Task Name Work Duration Start Finish Resource Names | 

41352492 © Go-live plan approved ihr | 1 day Fri 22-05-13 Mon 22-05-16 467 Technology and Security SME CoA 

4.15.2.4.8.3 | CAB Submission Preparation 3 hrs 1 day Mon 22-05-16 Tue 22-05-17 468 Developer CoA 

4.15.2.4.8.4 — . CAB Approval . ihr 1 day Tue 22-05-17 Wed 22-05-18 469 Technology and Security SME CoA 

4.15.2.4.8.5 ... Launch solution 1 hr 1 day Wed 22-05-18 Thu 22-05-19 470 Developer CoA 

4.15.2.5 Portal Updates - 99 hrs 35 days Tue 23-01-17 Mon 23-03-06 __ MW a. 

4.15.2.5.1 Design 20 hrs 5 days Tue 23-01-17 Mon 23-01-23 471FS+180 days Developer CoA[53%] 

4.15.2.5.2 Development/Configure :40 hrs 10 days Mon 23-01-23 Mon 23-02-06 473 Developer CoA[53%] — 

4.15.2.5.3 Testing | | 10 hrs 5 days Mon 23-02-06 Mon 23-02-13 474 Application Support CoA[27%] 

4.15.2.5.4 Redevelopment for bug fixes 10 hrs 5 days Mon 23-02-13 Fri 23-02-17 475 Developer CoA[2796] 

4.15.2.5.5 Retesting |. 5 hrs :2 days | iFri 23-02-17 ‘Wed 23-02-22 476 Application Support CoA[33%] - 

415.256 — Training 5 hrs 2 days ‘Wed 23-02-22 Fri 23-02-24 .. 477 Developer CoA[33%] 

4.15.2.5.7 UAT sign-off E hr .1 day .Fri 23-02-24 Mon 23-02-27 _ 478 Developer CoA[13%] 

4.15.2.5.8 Go Live 8 hrs 5 days Mon 23-02-27 Mon 23-03-06 m" | 

4.15.2.5.8.1 _ Go live plan 2 hrs 1day Mon 23-02-27 Tue 23-02-28 479 Developer CoA | 

4.15.2.5.8.2 Go-live plan approved 1hr 1 day Tue 23-02-28 Wed 23-03-01 . 481 Technology and Security SME CoA 

4.15.2.5.8.3 _ CAB Submission Preparation 3 hrs | 1 day Wed 23-03-01 _:Thu 23-03-02 482 Developer CoA 

4.15.2.5.8.4 CAB Approval '1hr :1 day Thu 23-03-02 Fri 23-03-03 483 Technology and Security SME CoA 

4.15.2.5.8.5 | Launch solution 1hr 1day | Fri 23-03-03 “Mon 23-03-06 | .. 484 Developer CoA 

4.15.2.6 Portal Updates 99 hrs 35 days Fri 23-10-27 Wed 23-12-13 | rr 

4.15.2.6.1 Design 20 hrs .5 days Fri 23-10-27 Fri 23-11-03 485FS+180 days Developer CoA[53%] 

4.15.2.6.2 Development/Configure 40 hrs 10 days Fri 23-11-03 ‘Thu 23-11-16 487 Developer CoA[53%] | 

4.15.2.6.3 Testing 7 10 hrs 5 days. Thu 23-11-16. Thu 23-11-23 488 Application Support CoA[27%] 

4.15.2.6.4 Redevelopment for bug fixes :10 hrs 5 days Thu 23-11-23 Thu 23-11-30 489 Developer CoA[27%] — 

4.15.2.6.5 Retesting .5 hrs 2 days Thu 23-11-30 Mon 23-12-04 490 Application Support CoA[33%] - 

4.15.2.6.6 Training 5 hrs ..2 days Mon 23-12-04 Wed 23-12-06 491 Developer CoA[33%] 

4.15.2.6.7 _ UAT sign-off 1hr 1 day Wed 23-12-06 Wed 23-12-06 492 Developer CoA[13%] 

4.15.2.6.8 _ Go Live 8 hrs :5 days _ Wed 23-12-06 Wed 23-12-13 | 

4.15.2.6.8.1 | Go live plan 2 hrs 1 day Wed 23-12-06 Thu 23-12-07 493 Developer CoA 

4.15.2.6.8.2 Go-live plan approved — . ihr 1 day Thu 23-12-07 Fri 23-12-08 __ 495 Technology and Security SME CoA 

4.15.2.6.8.3 CAB Submission Preparation. 3hrs 1day Fri 23-12-08 Mon 23-12-11 496 Developer CoA | | 

4.15.2.6.8.4 CAB Approval _ 1 hr 1day | Mon 23-12-11 Tue 23-12-12 497 Technology and Security SME CoA 

4.15.2.6.8.5 Launch solution 1hr 1day _ Tue 23-12-12 Wed 23-12-13 498 Developer CoA 

415.3 . Mobile Apps (IOS/Android) Interface 8,092 hrs 1022 days Wed 21-02-03 Thu 24-11-07 

4.15.3.1 Mobile Apps Development V1 2,998 hrs 188 days Wed 21-02-03 Mon 21-10-18 | 7 | 
4.15.3.1.1 | Design 1,300 hrs 60 days Wed 21-02-03 Tue 21-04-27 407 Business Analyst[67?6], Developer 1[67%],Developer 2[67%] 
4.15.3.1.2 Development/Configure 1,500 hrs 100 days Tue 21-04-27 Thu 21-09-09 .502 Data Analyst[67?6], Developer 1[67?5], Developer 2[6796] 
4.15.3.1.3 Testing | T" | 60 hrs 6 days Thu 21-08-09 Thu 21-09-16 503 Data Analyst{67%], Developer 1[67%],Developer 267%] — 
4.15.3.1.4 Redevelopment for bug fixes 30 hrs 5 days Thu 21-09-16 ‘Thu 21-09-23 _ 504 Developer 2[80%] 

415315 — Retesting 30 hrs 5 days . Thu21-09-23 Thu 21-09-30 505 Developer 2[80%] _ as a VUE | 
4.15.3.1.6 Training 60 hrs .6 days Thu 21-09-30 Thu 21-10-07 506 Data Analyst[67%],Developer 1[67%],Developer 2[6796] 
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WBS Task Name Work 
4.15.3.1.7 UAT sign-off 2 hrs 
4.15.3.1.8 Go Live — 16 hrs 
4.15.3.1.8.1 : Go live plan 4 hrs 
4.15.3.1.82 Go-live plan approved 2 hrs 
4.15.3.1.8.3 .. CAB Submission Preparation. 6 hrs 
4.15.3.1.8.4 CAB Approval 2 hrs 
4.15.3.1.8.5 Launch solution 2 hrs | 
4.15.3.2 . Mobile Apps Development V2 1,698 hrs. 
4.15.3.2.1 Design 600 hrs 
4.15.3.2.2 Development/Configure 900 hrs 
4.15.3.2.3 Testing. | 60 hrs 
4.15.3.2.4 Redevelopment for bug fixes 30 hrs 
4.15.3.2.5 Retesting 30 hrs 
4.15.3.2.6 Training 60 hrs 
4.15.3.2.7 UAT sign-off 2 hrs 
4.15.3.2.8 — GoLive - 16 hrs 
4.15.3.2.8.1 Go live plan 4 hrs 
4.15.3.2.8.2 Go- -live plan approved 2 hrs 
4.15.3.2.8.3 CAB Submission Preparation 6 hrs 
4.15.3.2.8.4 CAB Approval 2 hrs 
4.15.3.2.8.5 Launch solution 2 hrs 
4.15.3.3 Mobile Apps Development V3 1,698 hrs 
4.15.3.3.1 Design 600 hrs 
4 15.3.3.2 Development/Configure ..900 hrs 
4.15.3.3.3 Testing — . .60 hrs. 
4.15.3.3.4 Redevelopment for bug fixes :30hrs . 
4.15.3.3.5 _Retesting 30 hrs 
4.15.3.3.6 Training |. 60 hrs 
415.337 UAT sign-off 2hrs 
415.338 — Go Live 16 hrs 
4.15.3.3.8.1 Go live plan 4hrs 
4.15.3.3.8.2 Go-live plan approved 2 hrs 
4.15.3.3.8.3 _ CAB Submission Preparation 6 hrs 
4.15.3.3.8.4 | 2 hrs 


CAB Approval 
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Duration 


:1 day 
_ Sdays 
.1 day 
:1 day 


1 day 


1 day 


| d day | 
128 days 


40 days 


60 days 


6 days. 
5 days 


5 days | 


6 days 


‘1 day 


_5 days 
.1 day 
.1day, 
:1 day 
1 day 


1 day 


128 days 
40 days 
60 days 
6 days | 
5 days … 
5 days. 


:6 days 


1 day 


5 days 


1 day 
1 day 


1 day 
‘1 day 


Sta rt 


Thu 21-10-07 


Fri 21-10-08 


Fri 21-10-08 
Tue 21-10-12 
Wed 21-10-13 


Thu 21-10-14 


Fri 21-10-15 


Mon 22-05-09 


Mon 22-05-09 


— Wed 22-06-29 
Mon 22-09-19 
Tue 22-09-27 


Tue 22-10-04 


Mon 22-10-10 


Tue 22-10-18 


Wed 22-10- 19 
Wed 22-10- 19 
Thu 22- 10-20 


Fri 22-10-21 


Mon 22-10-24 


Tue 22-10-25 
Mon 23-05-15 


Mon 23-05-15 


“Thu 23-07-06 
‘Mon 23-09-25 


Tue 23-10-03 


‘Mon 23-10-09 


Mon 23-10-16 


:Tue 23-10-24 


Wed 23-10-25 
Wed 23-10-25 


Wed 23-10-25 
Thu 23-10-26 


Fri 23-10-27 
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Finish 


Fri 21-10-08 


Mon 21-10-18 
‘Tue 21-10-12 
Wed 21-10-13 
Thu 21-10-14 


Fri 21-10-15 


Mon 21-10-18 


Wed 22-10-26 
Wed 22-06-29 


‘Mon 22-09-19 


Tue 22-09-27 


Tue 22-10-04 . 


Mon 22-10-10 
Tue 22-10-18 


Wed 22-10-19 
Wed 22-10-26 


Thu 22-10-20 


Fri 22-10-21 
Mon 22-10-24 


Tue 22-10-25 


Wed 22-10-26 
Tue 23-10-31 


Thu 23-07-06 


‘Mon 23-09-25 


Tue 23-10-03 
Mon 23-10-09 
Mon 23-10-16 
Tue 23-10-24 


Wed 23-10-25 


Tue 23-10-31 
Wed 23-10-25 
Thu 23-10-26 
Fri 23-10-27 


Mon 23-10-30 


Predecessors 


-Resource Names 
507 Technology and Security SME CoA[1396], Technology and Security SME 
 AAHC[1394] 


— 508 Developer 1[27%],Developer 2[2796] - 
_ 510 Developer 1[27%], Developer 2[27%] 


511 Developer 1[2796], Developer 2[27%] 
Technology and Security SME CoA[13%], Technology and Security SME 


512 
AAHC[13%] 


513 Developer 1[13%], Developer 2113%] 


514FS+150 May 


528FS+150 days 


Business Analyst[67%], Developer 1[6796],Developer 2[6796] 


516 Data Analyst[67%], Developer 1[67%], Developer 2[6796] 

517 Data Analyst[6775], Developer 1[67%], Developer 2[67%] 

518 Developer 2[80%] _ 

519 Developer 2[80%] 

520 Data Analyst[44%], Developer 1[44%], Developer 2[44%] | 

521 Technology and Security SME CoA[13%], Technology and Security SME 
AAHC[1396] | 

522 Developer 1[27%], Developer 2[2796] 

524 Developer 1[27?6], Developer 2[27%] 

525 Developer 1[27?6], Developer 2[27%] 

Technology and Security SME CoA[13%], Technology and Security SME 

AAHC[13%] WN | 

527 Developer 1[13%],Developer 2[1396] 


526 


Business Analyst[67%], Developer 1[6796], Developer 2[67%] 


530 Data Analyst[6794], Developer 1[67%], Developer 2[67%] 
531 Data Analyst[67%],Developer 1[67%],Developer 2[67%] _ 
532 Developer 2[80%] _ 

533 Developer 2[80?6] 


534. Data Analyst[44%],Developer 1[44%], Developer 2[44%] 


Technology and Security SME CoA[13%], Technology and Security SME 


535 
AAHC[13%] 


"536 Developer 1[2796],Developer 2[27%] 


538 Developer 1[27%],Developer 2[27%] _ 
539 Developer 1[27%],Developer 2[27%] _ 
Technology and Security SME CoA[1396], Technology and Security SME 


540. 
` AAHC[13%] 
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4.15.3.3.8.5 
4.15.3.4 


4.15.3.4.1 


4.15.3.4.2 
4.15.3.4.3 
415.3.4.4 - 
4.15.3.4.5 
4.15.3.4.6. 


4.15.3.4.7 


415.348 —— 


4.15.3.4.8.1 


4.15.3.4.8.2 
4153483 — 


4.15.3.4.8.4 


4.15.3.4.8.5 
5 

5.1 

5.1.1 


6.2 


Task Name 


Launch solution | 
Mobile Apps Development V4 


Design 


Development/Configure 

| Testing mE | 
Redevelopment for bug fixes 
Retesting 
Training 


UAT sign-off 


Go Live 
_ Go live plan 
Go-live plan approved 
CAB Submission Preparation 


CAB Approval 


.. Launch solution | 
Phase 4 Communications and Engagement 
Phase 4 Evaluation & Ongoing sustainment 

Communications and promotions 

Interviews with service providers 

Streeter surveys 

Online tool 

Kiosks | 


E . Closeout 


" Update implemented state documentation | 


Complete Retrospective/Lessons Learned 


| | Transition to support 


Write Project Steering Committee closeout report & presentation 


Present Closeout Report 
Project Management 
Sponsor meetings 
Sponsor meetings 1 
Sponsor meetings 2 
Sponsor meetings 3 
Sponsor meetings 4 
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Work 
2hrs 
1,698 hrs - 


600 hrs 
900 hrs 


:60 hrs 


30 hrs 
30 hrs 
60 hrs 


2 hrs 


_16 hrs 


4 hrs 
2hrs. 


6 hrs 
2 hrs 


2 hrs 
124 hrs 
124 hrs 
56 hrs 
16 hrs 
10 hrs 
34 hrs 
8 hrs. 
89 hrs 


E 35 hrs 


36 hrs 


4 hrs 


12 hrs 
2 hrs 


1850hrs | 


124 hrs 
2 hrs 
2 hrs 


:2 hrs 


2 hrs 


Duration Start |. 
1day . Mon 23-10-30 
128 days. Tue 24-05-21 
:40 days Tue 24-05-21 
-60 days Fri 24-07-12 - 
6 days Wed 24-10-02 
5 days Wed 24-10-09 
5 days .. . Wed 24-10-16 
6 days Wed 24-10-23 
1 day Wed 24-10-30 
5 days Thu 24-10-31 
1day Thu 24-10-31 
1 day Fri 24-11-01 | 
1 day . Mon 24-11-04 
1day Tue 24-11-05 
| .1 day Wed 24-11-06 
.38 days” Fri 24-07-12 
38 days Fri 24-07-12 
:10 days Fri 24-07-12 
5 days Fri 24-07-26 
10 days Thu 24-08-01 . 
10 days Thu 24-08-15 . 
3 days Wed 24-08-28 
8.27 days Thu 24-11-07 
5 days Thu 24-11-07 
1 day Fri 24-11-15 
1day _ Fri 24-11-15 | 
.1 day Mon 24-11-18 
0.27 days Tue 24-11-19 
1396.2 days Wed 19-09-04 
1372.73 days Tue 19-09-10 
.1 day Tue 19-09-10 
1 day Tue 19-10-08 
1 day Tue 19-11-12 
1 day Tue 19-12-10 - 
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Finish 
Tue 23-10-31 


: Thu 24-11-07 


Wed 24-10-02 


Wed 24-10-09 
Wed 24-10-16 


Wed 24-10-23 
‘Wed 24-10-30 


Thu 24-10-31 


Thu 24-11-07 


.Fri 24-11-01 


Mon 24-11-04 


Tue 24-11-05 


Wed 24-11-06 


Thu 24-11-07 


Tue 24-09-03 


Tue 24-09-03 
Fri 24-07-26 
Thu 24-08-01 
Thu 24-08-15 
Wed 24-08-28 
Tue 24-09-03 


Wed 24-11-20 


Fri 24-11-15 


Fri 24-11-15 


Mon 24-11-18 . 


Tue 24-11-19 


Wed 24-11-20 
Fri 24-11-01 


Tue 24-10-08 
Tue 19-09-10 


Tue 19-10-08 
Tue 19-11-12 


-Tue 19-12-10 


:Predecessors 


|. 566 Data Analyst,Developer 1,Developer 2,Project Manager 


Resource Names 
541 Developer 1[13%], Developer 2[13%] 


Fri 24-07-12 542FS+150 days Business Analyst[67%],Developer 1[6796],Developer 2[6796] 


544 Data Analyst[67%], Developer 1[67%],Developer 2[67%] 

545 Data Analyst[67%], Developer 1[67%],Developer 2[67%] 

546 Developer 2[80%] 

547 Developer 2[80%] — | 

548 Data Analyst[44%], Developer 1[44%], Developer 2[44%] | | 
Technology and Security SME CoA[13%], Technology and Security SME 


549 
AAHC[13%] | 


550 Developer 1[27%], Developer 2[27%] 
552 Developer 1[27%],Developer 2[2796] 


_553 Developer 1[27%],Developer 2[27%] 


Technology and Security SME CoA[13%] Technology and Security SME 
— AAHC[1390] 7 | 
555 Developer 1[13%], Developer 2[13%] _ 


544 Communications and Engagement Consultant[4026] 


559 Communications and Engagement Consultant[40%] 
560 Communications and Engagement Consultant[40%] 
561 Communications and Engagement Consultant[4026] 
562 Communications and Engagement Consultant[40%] 


.556 Business Analyst 


Business Analyst[53%],Corporate Information Governance Leads 
CoA[53%],Data Analyst[53%], Developer 1[53%], Developer 

2[5396], Technology and Security SME CoA[53%], Technology and Security 
SME AAHC[5394], Procurement CoA[53%] Project Manager[53%] 


565 


Data Analyst[40%], Developer 1[40%], Developer 2[40%],Project 
__Manager[40%] | 
568 Program Manager 


Project Manager[1 96], Program Manager | 

Project Manager[13%], Program Manager[13%] 
Project Manager[13%],Program Manager[13%] 
[ 


3 
3 
3 
‘Project Manager[13?6], Program Manager[13?6] 
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WBS Task Name Work ` Duration | Start Finish Predecessors Resource Names =~ | 
7.1.5 Sponsor meetings 5 FANS. 1 day | Tue 20-01-14 Tue 20-01-14 Project Manager[13%],Program Manager[13%] 
7.1.6 Sponsor meetings 6 : 2 hrs 1 day Tue 20-02-11 Tue 20-02-11 Project Manager[13%],Program Manager[13?6] — 
7.1.7 Sponsor meetings 7 2 hrs 1 day R Tue 20-03-10 Tue 20-03-10 Project Manager[13%],Program Manager[1396] _ 
7.1.8 Sponsor meetings 8 2 hrs 1 day Tue 20-04-14 Tue 20- 04-14 Project Manager[13%],Program Manager[13%] 
7.1.9 Sponsor meetings 9 _ 2 hrs :1 day Tue 20-05-12 Tue 20-05-12 — Project Manager[13%],Program Manager[13%] 
7.1.10 Sponsor meetings 10 2 hrs '1 day .Tue 20-06-09 ‘Tue 20-06-09 © Project Manager[13%],Program Manager[13%] 
7.1.11 Sponsor meetings 11 2 hrs 1 day Tue 20-07-14 Tue 20-07-14 Project Manager[13?6], Program Manager[13%] 
7.1.12 Sponsor meetings 12 2 hrs 1 day Tue 20-08-11 Tue 20-08-11 Project Manager[13?6], Program Manager[13%] 
7.1.13 Sponsor meetings 13 2 hrs day _ Tue 20-09-08 ‘Tue 20-09-08 ‘Project Manager[1396], Program Manager[1396] 
7.1.14 Sponsor meetings 14 2 hrs iday Tue 20-10-13 Tue 20-10-13 Project Manager[13%],Program Manager[13%] 
7.1.15 Sponsor meetings 15 2 hrs | 1 day Tue 20-11-10 — Tue 20-11-10 Project Manager[13%],Program Manager[13%] 
7.1.16 Sponsor meetings 16 | 2 hrs 1 day — Tue 20-12-08 Tue 20-12-08 ‘Project Manager[13%],Program Manager[13%] _ 
7.1.17 Sponsor meetings 17 2 hrs Iday_ Tue 21-01-12 Tue 21-01-12 Project Manager{13%], Program Manager[1396] 
7118 Sponsor meetings 18 2 hrs 1 day Tue 21-02-09 Tue 21-02-09 Project. Manager[13?6], Program Manager[13?0] 
7.1.19 Sponsor meetings 19 2 hrs 1 day Tue 21-03-09 ‘Tue 21-03-09 Project Manager[1326], Program Manager[13%] - 
7.1.20 Sponsor meetings 20 2 hrs .1 day ‘Tue 21-04-13 Tue 21-04-13 Project Manager[13%],Program Manager[13%] 
7.1.21 Sponsor meetings 21 2 hrs č :1 day Tue 21-05-11 Tue 21-05-11 Project Manager[13%],Program Manager[13%] 
7.1.22 Sponsor meetings 22 2 hrs. 1 day Tue 21-06-08 Tue 21-06-08 Project Manager[13%],Program Manager[13%] 
7.1.23 Sponsor meetings 23 2 hrs 1 day Tue 21-07-13 Tue 21-07-13 Project Manager[13%],Program Manager[13%] 
7.1.24 Sponsor meetings 24 2 hrs 1 day Tue 21-08-10 Tue 21-08-10 ‘Project Manager[13%],Program Manager[13%] 
7.1.25 Sponsor meetings 25 | 2hrs | 1 day Tue 21-09-14 Tue 21-09-14 Project Manager[13%],Program Manager[13%] | 
7.1.26 Sponsor meetings 26 o 2hrs 1 day Tue 21-10-12 Tue 21-10-12 _.Project Manager[13%],Program Manager[1396] 
7.1.27 Sponsor meetings 27 2 hrs 1 day Tue 21-11-09 Tue 21-11-09 Project Manager[13%],Program Manager[13%] 
71.28 Sponsor meetings 28 :2 hrs 1 day Tue21-12-14 Tue 21-12-14 Project Manager[13%],Program Manager[13%] 
7.1.29 Sponsor meetings 29 2 hrs  1day — ‘Tue 22-01-11 _ Tue 22-01-11 Project Manager[13%],Program Manager[1396] 
7.1.30 Sponsor meetings 30 2 hrs .1 day Tue 22-02-08 Tue 22-02-08 Project Manager[13%],Program Manager[1396] 
7.1.31 Sponsor meetings 31 2 hrs 1 day Tue 22-03-08 Tue 22-03-08 Project Manager[13%],Program Manager[13%] 
7.1.32 Sponsor meetings 32 ¿2 hrs. 1 day Tue 22-04-12 Tue 22-04-12 Project Manager[13%],Program Manager[13%] 
7.1.33 Sponsor meetings 33 2 hrs :1 day Tue 22-05-10 Tue 22-05-10 Project Manager[1396], Program Manager[13%] 
7.1.34 Sponsor meetings 34 2 hrs 1 day Tue 22-06-14 Tue 22-06-14 Project Manager[13%], Program Manager[13%] 
7.1.35 Sponsor meetings 35 2 hrs 1 day Tue 22-07-12 ‘Tue 22-07-12 Project Manager[13%],Program Manager[13%] 
7.1.36 Sponsor meetings 36 2 hrs 1 day Tue 22-08-09 Tue 22-08-09 Project Manager[13%],Program Manager[1396] 
7.1.37 Sponsor meetings 37 2hrs 1 day Tue 22-09-13 Tue 22-09-13 Project Manager[13%],Program Manager[13%] 
7.1.38 Sponsor meetings 38 2 hrs | .1 day Tue 22-10-11 Tue 22-10-11 . Project Manager[13%],Program Manager[13%] 
7.1.39 Sponsor meetings 39 2 hrs 1 day Tue 22-11-08 Tue 22-11-08 Project Manager[1396],Program Manager[13?6] 
7.1.40 Sponsor meetings 40 2hrs — 1 day Ue 22-12-13 ‘Tue 22-12-13 Project Manager[13%],Program Manager[13%] 
7.1.41 Sponsor meetings 41 2 hrs 4 day Tue 23-01-10 Tue 23-01-10 ` Project Manager[13%],Program Manager[13%] 
7.1.42 Sponsor meetings 42 2 hrs 1 day Tue 23-02-14 Tue 23-02-14 Project Manager[13%],Program Manager[13*6] 
7.1.43 Sponsor meetings 43 2 hrs 1 day Tue 23-03-14 Tue 23-03-14 Project Manager[13%],Program Manager[1396] 
7.1.44 Sponsor meetings 44 2 hrs 1 day Tue 23-04-11 Tue 23-04-11 Project Manager[13%],Program Manager[1396] 
7.1.45 Sponsor meetings 45 2hrs 1 day Tue 23-05-09 Tue 23-05-09 Project Manager[13%],Program Manager[13%] 
7.1.46 Sponsor meetings 46 2 hrs 1 day Tue 23-06-13 Tue 23-06-13 © Project Manager[13%],Program Manager[13%] 
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WBS Task Name | Work Duration Eos ‘Start Finish Predecessors Resource Names _ l 
7.147 Sponsor meetings 47 2 hrs 1 day Tue 23-07-11 -Tue 23-07-11 Project Manager[13%],Program Manager[13%] 
7.1.48 Sponsor meetings 48 2 hrs :1 day Tue 23-08-08 . Tue 23-08-08 Project Manager[13?6], Program Manager[13%] 
7.1.49 Sponsor meetings 49 - 2 hrs. 1 day Tue 23-09-12 Tue 23-09-12 Project Manager[13?6], Program Manager[13*6] 
7.1.50 Sponsor meetings 50 :2 hrs :1 day Tue 23-10-10 Tue 23-10-10 Project Manager[13%],Program Manager[13%] | 
7.1.51 Sponsor meetings 51 2 hrs 1 day _ Tue 23-11-14 Tue 23-11-14 _ Project Manager[13%],Program Manager[13%] 
7.1.52 Sponsor meetings 52 2hrs 1day . Tue 23-12-12 ‘Tue 23-12-12 Project Manager[13%],Program Manager[13%] 
7.1.53 Sponsor meetings 53 2 hrs 1 day Tue 24-01-09 Tue 24-01-09 Project Manager[1396], Program Manager[13%] | 
7.1.54 Sponsor meetings 54 2 hrs 1 day Tue 24-02-13 Tue 24-02-13 Project Manager[13%],Program Manager[13%] _ 
7.1.55 Sponsor meetings 55 2hrs 1 day _ Tue 24-03-12 Tue 24-03-12 Project Manager[13%],Program Manager[13%] © 
7.1.56 Sponsor meetings 56 2 hrs ..1 day Tue 24-04-09 ‘Tue 24-04-09 Project Manager[13?6], Program Manager[13%] 
7.1.57 Sponsor meetings 57 2 hrs .1 day Tue 24-05-14 Tue 24-05-14 © . Project Manager[13%],Program Manager[13%] 
7.1.58 Sponsor meetings 58 2 hrs 1 day Tue 24-06-11 Tue 24-06-11 Project Manager[13%],Program Manager[13%] 
74,59 Sponsor meetings 59. 2 hrs :1 day ‘Tue 24-07-09 Tue 24-07-09 Project Manager[13%],Program Manager[13%] 
7.1.60 Sponsor meetings 60 2 hrs 1 day Tue 24-08-13 Tue 24-08-13 Project Manager[1396],Program Manager[1396] 
7.1.61 _ Sponsor meetings 61 2 hrs |l day Tue 24-09-10 Tue 24-09-10 Project Manager[13%],Program Manager[13%] 
7.1.62 Sponsor meetings 62 — 2 hrs .1 day Tue 24-10-08 Tue 24-10-08 Project Manager[13%],Program Mänager[13%] 
7.2 Project Team Meetings 810 hrs 1388.73 days Wed 19-09-04 Wed 24-10-23 
. . Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
7.2.1 Pr tT Meet 1 6h 1d Wed 19-09-04 Wed 19-09-04 
rue T ad : ü 2[13%],Program Manager[13%],Project Manager[13%] 
: : Business Analyst[1396],Data Analyst[1396], Developer 1[13%], Developer 
7.2.2 Project T Meet 2 6h 1d Wed 19-09-18 Wed 19-09-18 
Serer re Mire TER " ay : 2[1396],Program Manager[1396], Project Manager[1396] 
723 Ao ect Tean TNCS 6 hrs idi Wed 19-10-02 Wed 19-10-02 Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
> J 8 Y 2[1396], Program Manager[1396],Project Manager[13%] 
724 raed Tem Wd 6 hrs id Wed 19-10-16 Wed 19-10-16 Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
uud ! 8 y 211394], Program Manager[13%],Project Manager[1396] 
| Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
7.2.5 Pr tT Meet 5 6h 1d Wed19-10-30 Wed 19-10-30 
uf MM io C " a : p 2[13%],Program Manager[13%],Project Manager[13%] 
r | Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
7.2.6 Project Team Meetings 6 6 hrs '1 day Wed 19-11-13 Wed 19-11-13 i 
2[1396], Program Manager[1396],Project Manager[13%] 
Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Devel r 
7.2.7 Project Team Meetings 7 6 hrs 1 day Wed 19-11-27 Wed 19-11-27 A Malye Sg] y l à perd HS rel Develove 
2{13%],Program Manager[1396],Project Manager[13%] 
. : Business Analyst{13%],Data Analyst[13%], Developer 1[13%], Developer 
7.2.8 P tT Meet 8 6h 1d Wed 19-12-11 Wed 19-12-11 
ENI DR a ab du oie 2(13%],Program Manager[1396],Project Manager[13%] 
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WBS 


7.2.9 
7.20 
7241 
3:235 
7.2.13 
7.244 
7.2.15 
7.2.16 
7.2.17 
7.248 
7.2.19 
7.2.20 
7.2.21 


7.2.22 
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Task Name 


Project Team Meetings 9 

Project Team Meetings 10 
Project Team Meetings 11 
Project Team Meetings 12 
Project Team MESRINE 
Project Team Meetings 14 
Project Team Meetings 15 
Project Team Meetings 16 
Project Team Meetings 17 
Project Team Meetings 18 
Project Team Meetings 19 
Project Team Meetings 20 
Project Team Meetings 21 


Project Team Meetings 22 


à l'information 


"Work | 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


Duration 


1 day 


:1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 
1 day 
1 day 


1 day 


Start 


Fri 19-12-27 


Wed 20-01-08 


Wed 20-01-22 


Wed 20-02-05 


Wed 20-02-19 


Wed 20-03-04 


Wed 20-03-18 


Wed 20-04-01 


Wed 20-04-15 


Wed 20-04-29 


Wed 20-05-13 


Wed 20-05-27 


Wed 20-06-10 


Wed 20-06-24 


Finish 


Fri 19-12-27 


Wed 20-01-08 


Wed 20-01-22 


Wed 20-02-05 


Wed 20-02-19 


Wed 20-03-04 


Wed 20-03-18 


Wed 20-04-01 


Wed 20-04-15 


Wed 20-04-29 


Wed 20-05-13 


Wed 20-05-27 


Wed 20-06-10 


Wed 20-06-24 
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Predecessors 


Resource Names 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%],Developer 


2[1396],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[1396], Developer 1[13%], Developer 


: 2[1396], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 


2[1394], Program Manager[13?6], Project Manager[1396] 


Business Analyst[1376], Data Analyst[13%], Developer 1[1396], Developer 
2[1394],Program Manager[1396],Project Manager[13%] | 


Business Analyst[1396],Data Analyst[1396],Developer 1[13%], Developer 
2[1394], Program Manager[1396], Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
2[13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


2[1396],Program Manager[1396], Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 
2[1396], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 
2[1394], Program Manager[1394], Project Manager[139?6] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 


:2[1396],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396], Developer 1[13%], Developer 
2[1396], Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
2[1394], Program Manager[13*6], Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 


. 2[1396], Program Manager[13%], Project Manager[1396] 
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WBS 


7.2.23 
7.2.24 
7.2.25 
7.2.26 
7.2.27 
7.2.28 
7.2.29 
7.2.30 
7.2.31 
7.2.32 
7.2.33 
7.2.34 
7.2.35 


7.2.36 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 


Task Name 


Project Team Meetings 23 


Project Team Meetings 24 


Project Team Meetings 25 


Project Team Meetings 26 


Project Team Meetings 27 


Project Team Meetings 28 


Project Team Meetings 29 


Project Team Meetings 30 


Project Team Meetings 31 


Project Team Meetings 32 


Project Team Meetings 33 


Project Team Meetings 34 


Project Team Meetings 35 


Project Team Meetings 36 


à l'information 


Work | 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


: Duration 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


Start 


Wed 20-07-08 


Wed 20-07-22 


Wed 20-08-05 


Wed 20-08-19 


Wed 20-09-02 


Wed 20-09-16 


Wed 20-09-30 


Wed 20-10-14 


Wed 20-10-28 


Thu 20-11-12 


Wed 20-11-25 


Wed 20-12-09 


Wed 20-12-23 


Wed 21-01-06 
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Finish 


Wed 20-07-08 


Wed 20-07-22 


Wed 20-08-05 


Wed 20-08-19 


. Wed 20-09-02 


Wed 20-09-16 


. Wed 20-09-30 


Wed 20-10-14 


Wed 20-10-28 


Thu 20-11-12 


Wed 20-11-25 


Wed 20-12-09 


Wed 20-12-23 


Wed 21-01-06 


Predecessors 


Resource Names 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1396], Program Manager[1396], Project Manager[13%] 


Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 


'2[1394], Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


2[1396], Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 


' 211396], Program Manager[1396],Project Manager[1396] 


' Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 
211396], Program Manager[1396], Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1394],Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396], Developer 


2[1396], Program Manager[1396],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13?6], Developer 1[13%], Developer 
2[1396], Program Manager[1396],Project Manager[1394] 


Business Analyst[1396],Data Analyst(13%], Developer 1[13%], Developer 
2[13%], Program Manager[1396],Project Manager[13%] 


Business Analyst[1396],Data Analyst[1396], Developer 1[13%],Developer 
2[1396],Program Manager[13%], Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 


2[13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[1396],Project Manager[13%] 

Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[1396],Project Manager[13%] 
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WBS 


7.2.37 
7.2.38 
7.2.39 

7.2.40 
7.2.41 
7.2.42 
7.2.43 
7.2.44 
7.2.45 

7.246 

7247 
7.2.48 

7.2.49 


7.2.50 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 


Task Name | 


Project Team Meetings 37 


Project Team Meetings 38 


Project Team Meetings 39 


Project Team Meetings 40 


Project Team Meetings 41 


Project Team Meetings 42 


Project Team Meetings 43 


Project Team Meetings 44 


Project Team Meetings 45 


Project Team Meetings 46 


Project Team Meetings 47 


Project Team Meetings 48 


Project Team Meetings 49 


Project Team Meetings 50 


a l'information 


Work 


6 hrs 


‘6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


‘Duration 


1 day 


1 day 


‘1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


‘1 day 


1 day 


1 day 


1 day 


` Start 


Wed 21-01-20 


Wed 21-02-03 


Wed 21-02-17 


Wed 21-03-03 


Wed 21-03-17 


Wed 21-03-31 


Wed 21-04-14 


Wed 21-04-28 


Wed 21-05-12 


Wed 21-05-26 


Wed 21-06-09 


Wed 21-06-23 


Wed 21-07-07 


Wed 21-07-21 


Page 318 of 341 


Finish 


Wed 21-01-20 


Wed 21-02-03 


Wed 21-02-17 


Wed 21-03-03 


Wed 21-03-17 


Wed 21-03-31 


‘Wed 21-04-14 


Wed 21-04-28 


Wed 21-05-12 


Wed 21-05-26 


Wed 21-06-09 


Wed 21-06-23 


Wed 21-07-07 


Wed 21-07-21 


Predecessors 


2[1396],Program Manager[13%],Project Manager[1396] 


Resource Names 


Business Analyst[1396],Data Analyst[1396], Developer 1[1396],Developer 


2[1396],Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[139?6], Developer 1[1396],Developer 
2[1396],Program Manager[1396],Project Manager[1396] 


Business Analyst[13%], Data Analyst[1396], Developer 1[1396],Developer 


2[1396],Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 
'2[1326], Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 
2[13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%],Developer 
2[13%],Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


2[1396], Program Manager[1396], Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[13%], Developer 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 


2[13%],Program Manager[1396],Project Manager[1396] 


‘Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


2[1396], Program Manager[1396],Project Manager[13%] 


Business Analyst[1396],Data Analyst[1396],Developer 1[13%], Developer 
2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396], Developer 
2[1396], Program Manager[13?6], Project Manager [1396] 


Business Analyst[13%], Data Analyst[13?6], Developer 1[13%], Developer 
211394], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[1396], Developer 1[13%], Developer 
2[1394], Program Manager[1396], Project Manager[1396] 
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WBS Task Name Work | Duration >> Start Finish Predecessors Resource Names 
Busi Analyst[1396],Data Analyst[1396],Devel 1[1396], 
7251 Project Team Meetings 51 6 hrs 1 day Wed 21-08-04 Wed 21-08-04 Dane ANAA Tov) Date ANSE SPRL Developer d Sy Developer 
2[13%], Program Manager[1396], Project Manager[1396] 
; | Business Analyst[1396],Data Analyst{13%], Developer 1[13%], Developer 
7.2.52 P tT Meet 52 6h 1da Wed 21-08-18 Wed 21-08-18 
IR! RYDDHAU S y z E 2[13%], Program Manager[1396], Project Manager[1396] 
: Busi Analyst[1396],Data Analyst[1396],Devel 1[13?6], Devel 
7.2.53 Project Team Meetings 53 6 hrs 1 day Wed 21-09-01 Wed 21-09-01 usiness Analyst T= 72 Data ARNI PH Developer THL neve per 
.2[1396], Program Manager[1396],Project Manager[13%] 
| | Busi Analyst[1396],Data Analyst[13%], Devel 1[1396],D 
7.2.54 Project Team Meetings 54 6 hrs 1 day Wed 21-09-15 Wed 21-09-15 ad Developer 
2{13%],Program Manager[1396],Project Manager[13%] 
Busi Analyst[1396],Data Analyst[13%], Devel 1[13%], Devel 
7.2.55 Project Team Meetings 55 6 hrs 1 day Wed 21-09-29 Wed 21-09-29 Usiness Analyst Wate walls SLDEVODDFY'N LORIE 
2[1396],Program Manager[1396],Project Manager[13%] 
Busi Analyst[13%],Data Analyst[13%], Devel 1[13%],Devel 
7.2.56 Project Team Meetings 56 6 hrs 1 day Wed 21-10-13 Wed 21-10-13 UST eos ADU AU nalyst| devel Developer 13%] Developer 
2[13%],Program Manager[13%],Project Manager[13%] 
: | ` Business Analyst[13%], Data Analyst[13%], Developer 1[13%],Developer 
7.2.57 Project Team Meet 57 6h :1 da Wed 21-10-27 Wed 21-10-27 
J SERES i Y 211394], Program Manager[13%],Project Manager[13%] 
‘Busi Analyst[1396],Data Analyst[13%], Devel 1[13%],Devel 
7.2.58 Project Team Meetings 58 6 hrs 1 day Wed 21-11-10 Wed 21-11-10 eines Analyst 120M] E te a1, Developer {Hee Pevelopet 
2[1396],Program Manager[1396],Project Manager[1396] 
. Business Analyst[139?6], Data Analyst[13%], Developer 1[13%], Developer 
7.2.59 Project Team Meet 59 h 1 da Wed 21-11-24 Wed 21-11-24 | 
| J es ants r . 2[13%], Program Manager[13%],Project Manager[13%] 
Busi Analyst[13%],Data Analyst[13%], Devel 1[13%],Devel 
7.2.60 Project Team Meetings 60 6 hrs 1 day Wed 21-12-08 Wed 21-12-08 Gen Ana yerta] yet a Mam DEVelaper 
| 2[13%], Program Manager[1396],Project Manager[13%] 
. Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
7.2.61 Project Team Meetings 61 6h 1d Wed 21-12-22 Wed 21-12-22 
jec 8 i ii: 2[1396],Program Manager[13%],Project Manager[13%] 
Busi Analyst[13%],Data Analyst[13%], Devel 1/13%],Devel 
72.62 Project Team Meetings 62 6 hrs 1 day "Wed 22-01-05 Wed 22-01-05 ne CNP Rata FHS SL Developer en el DRIO 
2[1396], Program Manager[1396],Project Manager[13%] 
Busi Analyst[1396],Data Analyst[1396], Deve! 1[13%],Devel 
20.55 Project Team Meetings 63 6 hrs 1 day Wed 22-01-19 Wed 22-01-19 UR SS AT IE OL Data Anar) Develo pel TAR DEYD 
2[13%], Program Manager[1396],Project Manager[1396] 
Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Devel 
7.2.64 Project Team Meetings 64 6 hrs 1 day Wed 22-02-02 Wed 22-02-02 Uses DROSTO Bays toon pEr OA DYCIOFS 
2[1394], Program Manager[139e], Project Manager[13%] 
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Information Act /Révisé en vertu de la Loi sur l'accés 
a l'information 


WBS 


7.2.65 


7.2.66 


7.2.67 


7.2.68 


7.2.69 


7.2.70 


7.2.71 


7.2.72 


7.2.73 


7.2.74 


7.2.75 


7.2.76 


7.2.77 


7.2.78 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 


: Task Name 


Project Team Meetings 65 


Project Team Meetings 66 


Project Team Meetings 67 


Project Team Meetings 68 


Project Team Meetings 69 


Project Team Meetings 70 


Project Team Meetings 71 


Project Team Meetings 72 


Project Team Meetings 73 


Project Team Meetings 74 


Project Team Meetings 75 


Project Team Meetings 76 


Project Team Meetings 77 


Project Team Meetings 78 


à l'information 


Work 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


'6 hrs 


6 hrs 


6 hrs 


6 hrs 


:6 hrs 


6 hrs 


6 hrs 


6 hrs 


Duration 


1 day 


1 day 


1 day 


.1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


Start Finish 

Wed 22-02-16 Wed 22-02-16 
Wed 22-03-02 Wed 22-03-02 
Wed 22-03-16 Wed 22-03-16 
Wed 22-03-30 — Wed 22-03-30 
Wed22-04313 Wed 22-04-13 
Wed 22-04-27 Wed 22-04-27 
Wed 22-05-11 Wed 22-05-11 
Wed 22-05-25 Wed 22-05-25 
Wed 22-06-08 Wed 22-06-08 
Wed 22-06-22 Wed 22-06-22 
Wed 22-07-06 Wed 22-07-06 
Wed 22-07-20 Wed 22-07-20 
Wed 22-08-03 Wed 22-08-03 
Wed 22-08-17 Wed 22-08-17 
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Predecessors 


Resource Names 


Business Analyst[1396], Data Analyst[13%], Developer 1[1396], Developer 
2[1396], Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[1396], Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%],Developer 


2[1396],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[13%], Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 


2[13%],Program Manager[13%], Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[13?6], Project Manager[13%] 
Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[13?6], Project Manager[1396] 


Business Analyst[13%],Data Analyst[13%], Developer 1[1396], Developer 


2[13%], Program Manager[13?6], Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


2[1396], Program Manager[139?6], Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396], Developer 1[13%], Developer 


2[1396],Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[13%],Project Manager[1396] 
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WBS 


7.2.79 


7.2.80 


7.2.81 


7.2.82 


7.2.83 


7.2.84 


7.2.85. 


7.2.86 


7.2.87 


7.2.88 


7.2.89 


7.2.90 


7.2.91 


7.2.92 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 


Task Name 


Project Team Meetings 79 


Project Team Meetings 80 


Project Team Meetings 81 


Project Team Meetings 82 


Project Team Meetings 83 


Project Team Meetings 84 


Project Team Meetings 85 


Project Team Meetings 86 


Project Team Meetings 87 


Project Team Meetings 88 


Project Team Meetings 89 


Project Team Meetings 90 


Project Team Meetings 91 


Project Team Meetings 92 


à l'information 


' Work 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


‘6 hrs 


6 hrs 


6 hrs 


6 hrs 


Duration 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


Start 


Wed 22-08-31 


Wed 22-09-14 


Wed 22-09-28 


Wed 22-10-12 


Wed 22-10-26 


Wed 22-11-09 


Wed 22-11-23 


Wed 22-12-07 


Wed 22-12-21 


Wed 23-01-04 


Wed 23-01-18 


Wed 23-02-01 


Wed 23-02-15 


Wed 23-03-01 
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Finish 


Wed 22-08-31 


Wed 22-09-14 


Wed 22-09-28 


Wed 22-10-12 


Wed 22-10-26 


Wed 22-11-09 


Wed 22-11-23 


Wed 22-12-07 


Wed 22-12-21 


Wed 23-01-04 


Wed 23-01-18 


Wed 23-02-01 


Wed 23-02-15 


Wed 23-03-01 


Predecessors 


:2[13%],Program Manager[13%],Project Manager[13%] 


Resource Names 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%],Developer 
2[1396],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%],Developer 
2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst{13%], Developer 1[13%],Developer 


2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[13%], Developer 
211396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


'2[1394], Program Manager[13%],Project Manager[1396] 


Business Analyst[13%], Data Analyst[1396],Developer 1[1396],Developer 


:2[1396], Program Manager[1396],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2(13%],Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


2[13%], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


:2[13%],Program Manager[1326],Project Manager[1396] 


Business Analyst[13%], Data Analyst[13%], Developer 1[1396],Developer 
2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 
2[1394], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 


211396], Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[1394], Program Manager[13%],Project Manager[13%] 
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WBS | Task Name Work | Duration. Start Finish Predecessors — Resource Names 
Business Analyst[1396],Data Analyst[1396],Developer 1[13%], Developer 
7.2.93 P tT Meet 93 6h 1d Wed 23-03-15 Wed 23-03-15 
Poe) eee = AY T x 2[139*6], Program Manager[1396], Project Manager[13%] 
| ; . Business Analyst[1396], Data Analyst[13%], Developer 1[1396],Developer 
7.2.94 P tT Meet 94 h id Wed 23-03-29 Wed 23-03-29 
ae a aia PIS ii : i 2[13%],Program Manager[1396],Project Manager[13%] 
Business Analyst[1396],Data Analyst[1396], Developer 1[13%],Developer 
7.2.95 Project Team Meetings 95 6 hrs 1 day Wed 23-04-12 Wed 23-04-12 - Ystl E9) ysuitso) per HAU Be 
2(13%],Program Manager[1396],Project Manager[13%] 
Busi Analvst[1396], Data Analyst[13%], Devel 1[132],Devel 
7.2.96 Project Team Meetings 96 6 hrs 1 day Wed 23-04-26 Wed 23-04-26 usines ANANA RA Dara Ana yst 19A Developer TH aye) Developer 
2[1396],Program Manager[1396],Project Manager[1396] 
| Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
7.2.97 Project Team Meetings 97 6 hrs 1da Wed 23-05-10 .Wed 23-05-10 
Ne d 2[1396],Program Manager[13%],Project Manager[13%] 
: : i 13%],D Anal 13?6],D | 1[1396],D | 
7.2.98 Project Team Meetings 98 6 hrs 1 day Wed 23-05-24 Wed 23-05-24 Susiness Analys TOR pata analyst IO O Develop ard [det awe lo per 
2[13%], Program Manager[13?6], Project Manager[13%] 
. ; 'Business Analyst[13%],Data Analyst[13%], Developer 1[13%], Developer 
7.2.99 Project Team Meetings 99 6 hrs 1 day Wed 23-06-07 .Wed 23-06-07 2[13%],Program Manager[13%],Project Manager[1394] 
i 96 Anal 13%],D | 1[139 
7.2.100 Project Team Meetings 100 6 hrs 1 day Wed 23-06-21 Wed 23-06-21 Püsiness ANA YSN ta alata Ana SH 9 DEVE OPET 117e Developer 
; | 2[13%],Program Manager{[13%], Project Manager[13%] 
. . Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 
7.2.101 Project Team Meetings 101 6 hrs 1 da Wed 23-07-05 :Wed 23-07-05 
5] FERME Y 7 : 2{13%],Program Manager{13%J], Project Manager[1390] 
Busi Analyst[13%],Data Analyst[13%], Developer 1[13%], Deve! 
7.2.102 Project Team Meetings 102 6 hrs 1 day Wed 23-07-19 Wed 23-07-19 Us Analyst OLD RHEAU per TES HEV raper 
2[1396],Program Manager[13%],Project Manager[13%] 
| : Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 
7.2.103 Project Team Meetings 103 6 hrs 1 da Wed 23-08-02 Wed 23-08-02 
Es Seung Y a 211394], Program Manager{13%},Project Manager{13%] 
. . Business Analyst[1396], Data Analyst[13%], Developer 1[1396], Developer 
7.2.104 Project Team Meetings 104 6 hrs 1 da Wed 23-08-16 Wed 23-08-16 
ene : £ i 2(1396],Program Manager[13%],Project Manager[1396] 
Busi Analyst[1396],Data Analyst[1396],Devel 1[13%],Devel 
7.2.105 Project Team Meetings 105 6 hrs 1 day Wed 23-08-30 Wed 23-08-30 USE snas AA] bales OR DAY OIODOL = Lear DEVE ID pen 
2(13%],Program Manager[13%],Project Manager[1394] 
. | Business Analyst[13%],Data Analyst[1396],Developer 1[13%],Developer 
7.2.106 Project Team Meetings 106 6 hrs 1da Wed 23-09-13 Wed 23-09-13 
O Ha X n E 2[13%], Program Manager[13%],Project Manager[13%] 
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Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


WBS 


7.2.107 
7.2.108 
7.2.109 
7.24410 
72111 
7.2.112 
7.2.113 

7.2.114 
7.2.115 
7.2116 
723117 
7.2.118 

7219 


7.2.120 


Smart Cities Challenge Proposal Project Plan City of Airdrie 


Processed under the provisions of the Access to 
Information Act /Révisé en vertu de la Loi sur l'accés 


| Task Name 


Project Team Meetings 107 


Project Team Meetings 108 


Project Team Meetings 109 


Project Team Meetings 110 


Project Team Meetings 111 


Project Team Meetings 112 


Project Team Meetings 113 


Project Team Meetings 114 


Project Team Meetings 115 


Project Team Meetings 116 


Project Team Meetings 117 


Project Team Meetings 118 


Project Team Meetings 119 


Project Team Meetings 120 


à l'information 


Work 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


Duration 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


1 day 


'1 day 


1 day 


Start - 


Wed 23-09-27 
Wed 23-10-11 
Wed 23-10-25 
Wed 23-11-08 


Wed 23-11-22 


Wed 23-12-06 


Wed 23-12-20 


Wed 24-01-03 


Wed 24-01-17 


Wed 24-01-31 


Wed 24-02-14 


‘Wed 24-02-28 


Wed 24-03-13 


Wed 24-03-27 
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Finish - 


Wed 23-09-27 


Wed 23-10-11 


Wed 23-10-25 


Wed 23-11-08 


Wed 23-11-22 


Wed 23-12-06 


Wed 23-12-20 


Wed 24-01-03 


Wed 24-01-17 


Wed 24-01-31 


Wed 24-02-14 


Wed 24-02-28 


Wed 24-03-13 


Wed 24-03-27 


Predecessors 


Resource Names 


Business Analyst[1396], Data Analyst[139?6], Developer 1[13%], Developer 
2[13%], Program Manager[139?6], Project Manager[13%] 


Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 


2[1396], Program Manager[1396], Project Manager[1396] 


Business Analyst[1396], Data Analyst[1396], Developer 1[139?6], Developer 
2[1396],Program Manager[1396],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%],Developer 1[13%], Developer 
2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396], Data Analyst[1396],Developer 1/13%], Developer 
2{13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[1396],Developer 1[13%], Developer 


2[13946], Program Manager[13%],Project Manager[1396] 


Business Analyst[13%], Data Analyst[1396],Developer 1[1396],Developer 


2[1394], Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[1396],Developer 
2{13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 


2[1396],Program Manager[1396],Project Manager[1396] 


Business Analyst[1396],Data Analyst[1396],Developer 1[1396],Developer 
2[1396],Program Manager[{13%],Project Manager[1396] 


Business Analyst[13%], Data Analyst[13%], Developer 1[13%], Developer 
2[1396], Program Manager[1396],Project Manager[1396] 


Business Analyst[13%],Data Analyst[1396],Developer 1[13%],Developer 
2[1394],Program Manager[1396],Project Manager[13%] 


Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[13%],Project Manager[13%] 
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s 
7.2.122 
42:123 
7.2.124 
7.2.125 
7.2.126 
7.2.127 
7.2.128 
7.2.129 
7.2.130 
7.2.131 
7.2.132 
72133 


.7.2.134 
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Task Name 


Project Team Meetings 121 


Project Team Meetings 122 


Project Team Meetings 123 


Project Team Meetings 124 


Project Team Meetings 125 


Project Team Meetings 126 


Project Team Meetings 127 


Project Team Meetings 128 


Project Team Meetings 129 


Project Team Meetings 130 


Project Team Meetings 131 


Project Team Meetings 132 


Project Team Meetings 133 


Project Team Meetings 134 


à l'information 


Work 


6hrs 


6hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


6 hrs 


Duration 


1 day 


1 day 


1 day 


1 day 
> day 
n 
.1 day 


4 day 


1 day 


1 day 


1 day 


1 day 


1 day 


'1day 


Sta rt 


Wed 24-04-10 


Wed 24-04-24 


Wed 24-05-08 


Wed 24-05-22 


Wed 24-06-05 


Wed 24-06-19 


Wed 24-07-03 


Wed 24-07-17 


Wed 24-07-31 


Wed 24-08-14 


Wed 24-08-28 


Wed 24-09-11 


Wed 24-09-25 


Wed 24-10-09 
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Finish 


Wed 24-04-10 


Wed 24-04-24 


Wed 24-05-08 


Wed 24-05-22 


Wed 24-06-05 


Wed 24-06-19 


Wed 24-07-03 


Wed 24-07-17 


Wed 24-07-31 


Wed 24-08-14 


Wed 24-08-28 


Wed 24-09-11 


Wed 24-09-25 


Wed 24-10-09 


Predecessors 


‘Resource Names 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[1396], Developer 


2[1396],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396], Data Analyst[13%], Developer 1[13%], Developer 
2[1396],Program Manager[13%],Project Manager[13%] 

Business Analyst[13%], Data Analyst[13%], Developer 1[1396],Developer 
2[1396], Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 


2[1396],Program Manager[13%],Project Manager[1396] 


Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 
2[13%], Program Manager[1396],Project Manager[13%] 


‘Business Analyst[1396],Data Analyst[13%], Developer 1[1396],Developer 
2[13%], Program Manager[1396],Project Manager[13%] 


Business Analyst[13%],Data Analyst[13%], Developer 1[13%],Developer 
:2[13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[13%], Data Analyst[13%], Developer 1[1396],Developer 
2[13%],Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[139?6], Developer 


2[1396],Program Manager[13%],Project Manager[1396] 


‘Business Analyst[1396],Data Analyst[13%], Developer 1[13%],Developer 
2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13%], Developer 
2[13%], Program Manager[13%],Project Manager[13%] 


Business Analyst[1396],Data Analyst[13%], Developer 1[13?6], Developer 
2[13%], Program Manager{13%],Project Manager[1396] 
Business Analyst[1396],Data Analyst[13?6], Developer 1[13?6], Developer 
2[13»6], Program Manager[13?6], Project Manager[13%] 
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Business Analyst[13%],Data Analyst[13%], Developer 1[1396],Developer 


7.2.135 Project Team Meetings 135 6 hrs 1 day Wed 24-10-23 Wed 24-10-23 2113%] Program Manager[13%] Project Manager[13%] 
7.3 Schedule Management 538 hrs 1388.73 days Thu19-09-05 Thu 24-10-24 MM s 
7.3.1 Schedule Management 1 2 hrs 1 day Thu19-09-05 . Thu 19-09-05 Project Manager[13?76], Program Manager 
7.3.2 Schedule Management 2 _ 2 hrs 1 day Thu 19-09-12 Thu 19-09-12 ‘Project Manager[13%], Program Manager 
7.3.3 Schedule Management 3 2 hrs 1 day Thu 19-09-19 Thu 19-09-19 Project Manager[13%],Program Manager 
734 _ Schedule Management 4. 2hrs — | day . Thu 19-09-26 Thu 19-09-26 -Project Manager[13%],Program Manager 
7.3.5 Schedule Management 5 2 hrs .1 day Thu 19-10-03 Thu 19-10-03 Project Manager[13%],Program Manager 
7.3.6 Schedule Management 6 2 hrs 1 day Thu 19-10-10 Thu 19-10-10 | Project Manager[13%],Program Manager 
7.3.7 Schedule Management 7 2hrs 1day Thu 19-10-17 Thu 19-10-17 Project Manager[13%],Program Manager 
7.3.8 Schedule Management 8 .2 hrs 1 day Thu 19-10-24 Thu 19-10-24 Project Manager[13%],Program Manager 
7.3.9 Schedule Management 9 2 hrs 1 day Thu 19-10-31 Thu 19-10-31 Project Manager[13%],Program Manager . 
7.3.10 Schedule Management 10 2 hrs 1 day Thu 19-11-07 Thu 19-11-07 Project Manager[13%],Program Manager 
7.3.11 Schedule Management 11 2 hrs day | Thu 19-11-14 Thu 19-11-14 Project Manager[13%],Program Manager 
7.3.12 Schedule Management 12 2 hrs 1 day Thu 19-11-21 Thu19-11-21 Project Manager[13%],Program Manager 
7.3.13 Schedule Management 13 :2 hrs 1day. Thu 19-11-28 Thu 19-11-28 Project Manager[13%],Program Manager 
7.3.14 Schedule Management 14 2 hrs 1 day Thu 19-12-05 Thu 19-12-05 Project Manager[13%],Program Manager 
7.3.15 Schedule Management 15 :2 hrs :1 day Thu 19-12-12 Thu 19-12-12 Project Manager[13%],Program Manager 
7.3.16 Schedule Management 16 :2 hrs :1 day ‘Thu 19-12-19 Thu 19-12-19 Project Manager[13%],Program Manager 
7.3.17 Schedule Management 17 2 hrs 1 day ‘Fri 19-12-27 Fri 19-12-27 Project Manager[13?6], Program Manager 
7.3.18 Schedule Management 18 2 hrs 1 day Thu 20-01-02 Thu 20-01-02 Project Manager[13%], Program Manager 
7.3.19 _ Schedule Management 19 :2 hrs 1 day Thu 20-01-09 Thu 20-01-09 Project Manager[13%], Program Manager 
7.3.20 _ Schedule Management 20 _ 2 hrs ‘1 day Thu 20-01-16 Thu 20-01-16 Project Manager[13%],Program Manager 
7.3.21 . schedule Management 21. | 2 hrs 1 day Thu 20-01-23 ‘Thu 20-01-23 | Project Manager[13%],Program Manager 
7.3.22 Schedule Management 22 2 hrs 1 day Thu 20-01-30 Thu 20-01-30 Project Manager[13%],Program Manager 
7.3.23 Schedule Management 23 2 hrs 1 day Thu 20-02-06 Thu 20-02-06 Project Manager[13%],Program Manager 
7.3.24 Schedule Management 24 2 hrs 1 day Thu 20-02-13 Thu 20-02-13 Project Manager[13%],Program Manager 
"73.25 Schedule Management 25 2 hrs :1 day Thu 20-02-20 Thu 20-02-20 Project Manager[13%],Program Manager 
7.3.26 Schedule Management 26 | 2 hrs 1 day Thu 20-02-27 Thu 20-02-27 Project Manager[13%],Program Manager 
7.3.27 Schedule Management 27 :2 hrs 1day | _ Thu 20-03-05 | Thu 20-03-05 Project Manager[13%], Program Manager 
7328. _ Schedule Management 28 2hrs — '1 day Thu 20-03-12 . Thu 20-03-12 Project Manager[13%],Program Manager 
13:29 _ Schedule Management 29 _ 2 hrs 1 day T Thu 20-03-19 . Thu 20-03-19 _ Project Manager[13%],Program Manager 
7.3.30 . Schedule Management 30 22 hrs ‘1 day. Thu 20-03-26 Thu 20-03-26 Project Manager[13%],Program Manager 
7.3.31 Schedule Management 31 2 hrs ‘1 day | | Thu 20-04-02 Thu 20-04-02 Project Manager[13%],Program Manager 
7.3.32 Schedule Management 32 :2 hrs 1day Thu 20-04-09 X Thu 20-04-09 Project Manager[13%],Program Manager 
7.3.33 Schedule Management 33 _ 2 hrs ..1 day Thu 20-04-16 X Thu 20-04-16 Project Manager[13%],Program Manager 
7.3.34 — Schedule Management 34 2 hrs 1 day Thu 20-04-23 Thu 20-04-23 Project Manager[13%],Program Manager — 
7.3.35 . Schedule Management 35 2 hrs 1 day Thu 20-04-30 . Thu 20-04-30 Project Manager[13%],Program Manager 
7.3.36 Schedule Management 36 2hrs 1 day Thu 20-05-07 ‘Thu 20-05-07 . ‘Project Manager[13%],Program Manager 
7.3.37 Schedule Management 37 2 hrs .. day Thu 20-05-14 Thu 20-05-14 © Project Manager[13%],Program Manager 
7.3.38 Schedule Management 38 2 hrs :1 day ‘Thu 20-05-23 ‘Thu 20-05-21 © Project Manager[13%],Program Manager 
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7.3.89 Schedule Management 39 :2 hrs 1 day Thu 20-05-28 | Thu 20-05-28 Project Manager[13*6],Program Manager 
7.3.40 Schedule Management 40 2 hrs 1 day Thu 20-06-04 Thu 20-06-04 Project Manager{[13%], Program Manager 
7.3.41 _ Schedule Management 41 2 hrs 1 day Thu 20-06-11 :Thu 20-06-11 © Project Manager[13%],Program Manager 
7.3.42 .. Schedule Management 42. 2 hrs 1 day Thu 20-06-18 Thu 20-06-18 . ; Project Manager[13%],Program Manager 
7.3.43 Schedule Management 43 2 hrs ‘1 day Thu 20-06-25 Thu 20-06-25 Project Manager[13%],Program Manager 
7.3.44 Schedule Management 44 2hrs | 1 day Thu 20-07-02 Thu 20-07-02 Project Manager[13%],Program Manager 
7.3.45 Schedule Management 45 2 hrs 1 day Thu 20-07-09 Thu 20-07-09 Project Manager[13%],Program Manager 
7.3.46 Schedule Management 46 2 hrs 1 day Thu 20-07-16 Thu 20-07-16 Project Manager[13%],Program Manager 
7.3.47 Schedule Management 47 2 hrs 1 day Thu 20-07-23 = Thu 20-07-23 &. : Project Manager[13%],Program Manager 
7.3.48 Schedule Management 48 2 hrs 1day _ Thu 20-07-30 | Thu 20-07-30 Project Manager[13?6], Program Manager 
7.3.49 Schedule Management 49 2hrs 1 day Thu 20-08-06 Thu 20-08-06 ¿Project Manager[13%],Program Manager 
7.3.50 Schedule Management 50 | :2 hrs 1 day Thu 20-08-13 . Thu 20-08-13 Project Manager[13%],Program Manager 
7.3.51 Schedule Management 51 ¿2hrs 1 day Thu 20-08-20 Thu 20-08-20 Project Manager[13%],Program Manager 
7.3.52. Schedule Management 52 2 hrs .1 day Thu 20-08-27 Thu 20-08-27 Project Manager[13?6],Program Manager 
7.3.53 Schedule Management 53 2 hrs 1 day Thu 20-09-03 Thu 20-09-03 Project Manager[13%],Program Manager 
7.3.54 Schedule Management 54 | 2 hrs 1 day Thu 20-09-10 | Thu 20-09-10 ‘Project Manager[13%],Program Manager 
7.3.55 Schedule Management 55 | 2hrs 1 day Thu 20-09-17 Thu 20-09-17 Project Manager[13%],Program Manager 
7.3.56 Schedule Management 56 2 hrs 1 day Thu 20-09-24 Thu 20-09-24 Project Manager[13%],Program Manager 
7.3.57 Schedule Management 57 2 hrs 1day Thu 20-10-01 . Thu 20-10-01 Project Manager[13%],Program Manager 
7.3.58 ... Schedule Management 58 2 hrs 1 day Thu 20-10-08 Thu 20-10-08 _: Project Manager[13%],Program Manager 
7.3.59 _ Schedule Management 59 .2 hrs 1day Thu 20-10-15 te Thu 20-10-15 Project Manager[13%],Program Manager 
7.3.60 Schedule Management 60 | 2 hrs 1 day Thu 20-10-22 Thu 20-10-22 Project Manager[13%],Program Manager _ 
7.3.61 Schedule Management 61 | 2 hrs 1 day Thu 20-10-29 Thu 20-10-29 Project Manager[13%],Program Manager 
7.3.62 Schedule Management 62 2hrs 1 day ‘Thu 20-11-05 Thu 20-11-05 Project Manager[13%],Program Manager 
7.3.63 Schedule Management 63 2 hrs 1 day Thu 20-11-12 . Thu 20-11-12 Project Manager[13%],Program Manager 
7.3.64 Schedule Management 64 2 hrs 1 day Thu 20-11-19 ‘Thu 20-11-19 Project Manager[13%],Program Manager 
7.3.65 Schedule Management 65 2 hrs 1 day Thu 20-11-26 ‘Thu 20-11-26 Project Manager[13%],Program Manager 
7.3.66 | Schedule Management 66 2 hrs .1 day Thu 20-12-03 Thu 20-12-03 Project Manager[13%],Program Manager _ 
7.3.67 Schedule Management 67 2 hrs 1 day Thu 20-12-10 Thu 20-12-10 Project Manager[13%],Program Manager 
7.3.68 Schedule Management 68 2 hrs 1 day Thu 20-12-17 Thu 20-12-17 . _ Project Manager[13%],Program Manager 
7.3.69 Schedule Management 69 :2 hrs 1 day Thu 20-12-24 Thu 20-12-24 Project Manager[13%],Program Manager 
7.3.70 Schedule Management 70 2 hrs 1 day | Thu 20-12-31 Thu 20-12-31 Project Manager[13%],Program Manager 
7.3.71 Schedule Management 71 2 hrs 1 day Thu 21-01-07 Thu 21-01-07 Project Manager[13%],Program Manager 
7.3.72 Schedule Management 72 2 hrs 1 day :Thu 21-01-14 Thu 21-01-14 Project Manager[13%],Program Manager 
7.3.73 Schedule Management 73 2 hrs 1 day. Thu 21-01-21 Thu 21-01-21 Project Manager[1396],Program Manager 
7.3.74 Schedule Management 74 2 hrs 1 day Thu 21-01-28 — Thu 21-01-28 Project Manager[1396],Program Manager 
7.3.75 Schedule Management 75 2 hrs 1 day Thu 21-02-04 Thu 21-02-04 Project Manager[13%],Program Manager 
7.3.76 Schedule Management 76 2 hrs 1 day Thu 21-02-11 = Thu 21-02-11 Project Manager[13%],Program Manager 
7.3.77 Schedule Management 77  2hrs '1 day Thu 21-02-18 Thu 21-02-18 Project Manager[13%], Program Manager 
7.3.78 Schedule Management 78 | -2 hrs 1 day Thu 21-02-25 . Thu 21-02-25 Project Manager[13%],Program Manager 
7.3.79 Schedule Management 79 2 hrs H day Thu 21-03-04 Thu 21-03-04 Project Manager[13%], Program Manager 
7.3.80 Schedule Management 80 2 hrs 1 day ‘Thu 21-03-11 Thu 21-03-11 Project Manager[13%],Program Manager 
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7.3.81 s Schedule Management 81 2 hrs 1 day Thu 21-03-18 Thu 21-03-18 Project Manager[13%],Program Manager 
7.3.82 Schedule Management 82 2 hrs 1 day Thu 21-03-25 Thu 21-03-25 Project Manager[13%],Program Manager 
7.3.83 Schedule Management 83 2 hrs 1 day Thu 21-04-01 Thu 21-04-01 . Project Manager[13%],Program Manager 
7.3.84 — Schedule Management 84 2 hrs .1 day Thu 21-04-08 Thu 21-04-08 | Project Manager[13%],Program Manager 
7.3.85 Schedule Management 85 2 hrs 1 day. Thu 21-04-15 Thu 21-04-15 Project Manager[13%],Program Manager 
7.3.86 Schedule Management 86 2 hrs 1 day Thu 21-04-22 'Thu 21-04-22 Project Manager[13%],Program Manager 
7.3.87 - Schedule Management 87 .2 hrs 1 day | Thu 21-04-29 Thu 21-04-29 Project Manager[13%],Program Manager 
7.3.88. Schedule Management 88 2 hrs 1 day | Thu 21-05-06 Thu 21-05-06 Project Manager[13%],Program Manager 
7.3.89 Schedule Management 89 2hrs _ 1 day Thu 21-05-13 Thu 21-05-13 _ Project Manager[13%],Program Manager 
7.3.90 Schedule Management 90 2 hrs 1 day | Thu 21-05-20 Thu 21-05-20 _ Project Manager[13%],Program Manager 
7.3.91 ... Schedule Management 91 ¿2hrs 1 day Thu 21-05-27 | Thu21-05-27  . Project Manager[13%],Program Manager _ 
. 7.3.92 _ Schedule Management 92 ae: hrs .1 day Thu21-06-03 . Thu 21-06-03 © Project Manager[13%],Program Manager 
4393 Schedule Management 93 2 hrs 1 day Thu 21-06-10 Thu 21-06-10 Project Manager[13?6],Program Manager 
7.3.94 Schedule Management 94 2 hrs | 1 day Thu 21-06-17 Thu 21-06-17 Project Manager[13%j,Program Manager 
7.3.95 Schedule Management 95 :2 hrs 1 day Thu 21-06-24 Thu 21-06-24 Project Manager[13%],Program Manager 
7.3.96 _ Schedule Management 96 2 hrs 1 day Fri 21-07-02  Fri21-07-02 © Project Manager[13%],Program Manager 
7.3.97 Schedule Management 97 2 hrs :1 day Thu 21-07-08 Thu 21-07-08 Project Manager[13%],Program Manager — 
7.3.98 Schedule Management 98 2 hrs 1 day Thu 21-07-15 Thu 21-07-15 Project Manager[13%],Program Manager _ 
7.3.99 Schedule Management 99 2 hrs 1 day  .Thu21-07-22 | Thu 21-07-22 Á Project Manager[13%],Program Manager 
7.3.100 Schedule Management 100 2hrs. tday . Thu 21-07-29 Thu21-07-29 | ‘Project Manager[13?76], Program Manager 
7.3.101 Schedule Management 101 :2 hrs 1 day Thu 21-08-05 :Thu 21-08-05 ‘Project Manager[13%],Program Manager 
7.3.102 Schedule Management 102 2 hrs 1 day Thu 21-08-12 = Thu 21-08-12 | Project Manager[13%],Program Manager 
7.3.103 Schedule Management 103 2 hrs 1 day Thu 21-08-19 Thu 21-08-19 Project Manager[13%],Program Manager 
7.3.104 Schedule Management 104 2 hrs 1 day Thu 21-08-26 Thu 21-08-26 Project Manager[13%],Program Manager 
7.3.105 Schedule Management 105 2 hrs | .1 day Thu 21-09-02 :Thu 21-09-02 _ Project Manager[13%],Program Manager 
7.3.106 Schedule Management 106 2 hrs 1 day Thu 21-09-09 Thu 21-09-09 — Project Manager[13%],Program Manager - 
7.3.107 Schedule Management 107 2 hrs | 1 day Thu 21-09-16 Thu 21-09-16 Project Manager[13%],Program Manager 
7.3.108 Schedule Management 108 2hrs | 1 day Thu 21-09-23 Thu 21-09-23 © Project Manager[13%],Program Manager — — 
7.3.109. Schedule Management 109 2 hrs. 1 day Thu 21-09-30 . Thu 21-09-30 Project Manager[13%],Program Manager 
7.3.110 Schedule Management 110 2 hrs 1 day Thu21-10-07 . Thu 21-10-07 Project Manager[13%],Program Manager 
7.3.1111 Schedule Management 111 | | 2 hrs 1 day Thu 21-10-14 Thu 21-10-14 Project Manager[13%],Program Manager 
7.3.112 Schedule Management 112 2 hrs 1 day Thu 21-10-21 Thu 21-10-21 Project Manager[13%],Program Manager 
7.3.113 Schedule Management 113 _.2 hrs 1 day | Thu 21-10-28 Thu 21-10-28 Project Manager{[13%], Program Manager 
7.3.114 Schedule Management 114 2 hrs 1 day Thu 21-11-04 Thu 21-11-04 Project Manager{13%], Program Manager 
7.3.115 Schedule Management 115 2hrs 1day Fri 21-11-12 Fri 21-11-12 “Project Manager[1396]),Program Manager __ 
7.3.116 Schedule Management 116 2hrs .1 day Thu 21-11-18 Thu 21-11-18 Project Manager[13%],Program Manager _ 
7.3.117 _ Schedule Management 117 2 hrs 1 day Thu21-11-25 Thu 21-11-25 Project Manager[13%], Program Manager 
‘1.3. 118 Schedule Management 118 2 hrs _1day Thu 21-12-02 Thu 21-12-02 Project Manager[13?6], Program Manager 
7.3.119 Schedule Management 119 - 2 hrs 1 day Thu 21-12-09 . Thu 21-12-09 Project Manager[13%],Program Manager 
7.3.120 Schedule Management 120 2 hrs '1 day :Thu 21-12-146 _:Thu21-12-16 Project Manager[13%], Program Manager 
7.3.121 Schedule Management 121 2hrs 1 day | Thu21-12-23 Thu 21-12-23 Project Manager{13%], Program Manager 
7.3.122 Schedule Management 122 2 hrs 1day Thu 21-12-30 Thu 21-12-30 Project Manager[1396],Program Manager 
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7.3.123 Schedule Management 123 2 hrs 1 day Thu 22-01-06 . Thu 22-01-06 Project Manager[1326], Program Manager 
7.3.124 Schedule Management 124 2 hrs :1 day Thu 22-01-13 Thu 22-01-13 Project Manager[13%],Program Manager 
UB. . Schedule Management 125 2 hrs 1 day | Thu 22-01-20 Thu 22-01-20 Project Manager[13%],Program Manager 
2.3.28 Schedule Management 126 2hrs | 1 day ... ;Thu22-01-27 Thu 22-01-27 Project Manager[13%],Program Manager 
3.127 Schedule Management 127 2 hrs 1 day Thu 22-02-03 ‘Thu 22-02-03 Project Manager[13%],Program Manager 
7.3.128 Schedule Management 128 2hrs 1 day Thu 22-02-10 Thu 22-02-10 _: Project Manager[13%],Program Manager 
7.3.129 Schedule Management 129 2 hrs day | Thu 22-02-17 Thu 22-02-17 Project Manager[13%],Program Manager 
7.3.130 . Schedule Management 130 2hrs | 1 day Thu 22-02-24 Thu 22-02-24 Project Manager[13%],Program Manager 
7.3.131 _ Schedule Management 131 :2 hrs 1day Thu 22-03-03 Thu 22-03-03 Project Manager[13%],Program Manager 
13,132. _ Schedule Management 132 2 hrs 1day | Thu 22-03-10 Thu 22-03-10 | Project Manager[1396], Program Manager 
7.3.1323 Schedule Management 133 2 hrs 1 day Thu 22-03-17 :Thu 22-03-17 — Project Manager[13%],Program Manager _ 
7.3.134 Schedule Management 134 2 hrs 1 day Thu 22-03-24 — Thu 22-03-24 Project Manager[13%], Program Manager 
7.3.135 Schedule Management 135 .2hrs — ¿1day | Thu22-03-31 Thu 22-03-31 Project Manager[13%],Program Manager 
7.3.136 . Schedule Management 136 2hrs | 1 day. Thu 22-04-07 Thu 22-04-07 Project Manager[13%],Program Manager 
75:137 _ Schedule Management 137 2 hrs 1 day Thu 22-04-14 :Thu 22-04-14 Project Manager[13%],Program Manager 
7.3.138 _ Schedule Management 138 2 hrs 1 day | Thu 22-04-21 Thu 22-04-21 Project Manager[13%],Program Manager 
7.3.139 Schedule Management 139 :2 hrs 1 day  :Thu22-04-28 Thu 22-04-28 Project Manager[13%],Program Manager 
73.140. Schedule Management 140 2 hrs .1 day Thu 22-05-05 Thu 22-05-05 Project Manager[13?6], Program Manager 
7.3.141 Schedule Management 141. 2 hrs 1 day Thu 22-05-12 . Thu 22-05-12 Project Manager[13%],Program Manager 
7.3.142 Schedule Management 142 2hrs | 1 day Thu 22-05-19 . Thu 22-05-19 Project Manager[13%],Program Manager 
7.3.143 Schedule Management 143 2hrs. 1 day Thu 22-05-26 | Thu 22-05-26 _ Project Manager[1326], Program Manager 
7.3.144 Schedule Management 144 2 hrs 1 day Thu 22-06-02 Thu 22-06-02 Project Manager[13%],Program Manager 
7.3.145 _ Schedule Management 145 2 hrs 1 day Thu 22-06-09 . Thu 22-06-09 Project Manager[13%],Program Manager 
7.3.146 Schedule Management 146 2 hrs 1 day ‘Thu 22-06-16 ‘Thu 22-06-16 Project Manager[1326], Program Manager 
7.347 Schedule Management 147 2 hrs 1 day Thu 22-06-23 . Thu 22-06-23 ' Project Manager[13%],Program Manager 
7.3.148 Schedule Management 148 2 hrs 1 day Thu 22-06-30 Thu 22-06-30 Project Manager[1396],Program Manager 
7.3.149 Schedule Management 149 2 hrs :1 day Thu 22-07-07 Thu 22-07-07 Project Manager[1326],Program Manager 
3.3.4350 — Schedule Management 150 _ 2 hrs 1 day Thu 22-07-14 . Thu 22-07-14 Project Manager[13%],Program Manager 
72.15). Schedule Management 151 2 hrs .1 day Thu 22-07-21 Thu 22-07-21 Project Manager[13%],Program Manager 
13152 Schedule Management 152 .2 hrs 1 day Thu 22-07-28 Thu22-0728 .— Project Manager[13%],Program Manager 
7,3.153 Schedule Management 153 2 hrs ‘1 day Thu 22-08-04 Thu 22-08-04 Project Manager[13%],Program Manager 
7.3.154 Schedule Management 154 2 hrs -1day Thu 22-08-11 Thu 22-08-11 Project Manager[13%],Program Manager 
7.3.155 Schedule Management 155 . 2 hrs .1 day Thu 22-08-18 Thu 22-08-18 Project Manager[13%],Program Manager 
7.3.156 Schedule Management 156 2 hrs 1 day. Thu 22-08-25 Thu 22-08-25 Project Manager[13%],Program Manager 
7.3.157 Schedule Management 157 2 hrs 1 day | Thu 22-09-01 Thu 22-09-01 Project Manager[13%],Program Manager 
7.3.158 Schedule Management 158 | 2 hrs 1 day Thu 22-09-08 Thu 22-09-08 Project Manager[1396], Program Manager _ 
7.3.159 Schedule Management 159 . :2 hrs 1day | Thu 22-09-15 A Thu 22-09-15 Project Manager[13%],Program Manager 
:7.3.160 . Schedule Management 160 2 hrs .1 day Thu 22-09-22 Thu 22-09-22 Project Manager[13%], Program Manager 
7.3.161 Schedule Management 161 2 hrs 1 day Thu 22-09-29 _ Thu 22-09-29 Project Manager[13%],Program Manager 
7.3.162 _ Schedule Management 162 2 hrs 1 day Thu 22-10-06 = Thu 22-10-06 Project Manager[13%],Program Manager 
23165 Schedule Management 163 2hrs 1 day . Thu 22-10-13 Thu 22-10-13 Project Manager[1376], Program Manager 
7.3.164 Schedule Management 164 2 hrs 1 day Thu22-10-20 Thu 22-10-20 Project Manager[13%],Program Manager _ 
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7.3.165 Schedule Management 165 2 hrs 1 day Thu 22-10-27 Thu 22-10-27 Project Manager[13%], Program Manager 
7.3.166. Schedule Management 166 2 hrs 1 day Thu 22-11-03 Thu 22-11-03 Project Manager[13%],Program Manager 
7.3.167 . Schedule Management 167 2 hrs 1 day Thu 22-11-10 Thu22-11-10 : Project Manager[13%],Program Manager 
7.3.168 Schedule Management 168 2 hrs 1 day :Thu 22-11-17 Thu 22-11-17 Project Manager[13%],Program Manager 
7.3.169 Schedule Management 169 2 hrs 1 day “Thu 22-11-24 Thu 22-11-24 Project Manager[13%],Program Manager 
7.3.170 Schedule Management 170 : 2hrs ‘1 day Thu 22-12-01 Thu 22-12-01 Project Manager[13%],Program Manager 
7.3.171 Schedule Management 171  2hrs 1 day Thu 22-12-08 Thu 22-12-08 Project Manager[13%],Program Manager 
723.172 _ Schedule Management 172 2 hrs 1 day Thu 22-12-15 ‘Thu 22-12-15 Project Manager[13%],Program Manager 
7.3.173 Schedule Management 173 2 hrs 1 day Thu 22-12-22 Thu 22-12-22 Project Manager[1326], Program Manager 
7.3.174 . Schedule Management 174 ; va hrs 1 day = Thu 22-12-29  ;Thu 22-12-29 Project Manager[13%],Program Manager 
7.3.175 Schedule Management 175 2hrs 1 day . Thu 23-01-05 ‘Thu 23-01-05 Project Manager[13%],Program Manager 
7.3.176 Schedule Management 176 2 hrs d day | Thu 23-01-12 ‘Thu 23-01-12 Project Manager[13%],Program Manager 
73177 Schedule Management 177 2 hrs 1 day Thu 23-01-19 Thu 23-01-19 _ Project Manager[13%],Program Manager. 
73.178 Schedule Management 178 2 hrs 1 day Thu 23-01-26 Thu 23-01-26 _ Project Manager[1326], Program Manager 
7.8179 Schedule Management 179 2 hrs 1 day Thu 23-02-02 Thu 23-02-02 | Project Manager[13%],Program Manager 
7.3.180 Schedule Management 180. 2 hrs 1 day Thu23-02-09 Thu 23-02-09 Project Manager[13%],Program Manager 
1.3 181. Schedule Management 181 2 hrs .1 day ‘Thu 23-02-16 Thu 23-02-16 Project Manager[13%],Program Manager 
7.3.182 Schedule Management 182 :2 hrs 1 day Thu 23-02-23 Thu 23-02-23 Project Manager[13%],Program Manager 
13183. . Schedule Management 183 2 hrs 1 day Thu 23-03-02  Thu23-03-02 _ Project Manager[13%],Program Manager _ 
7.3.184 Schedule Management 184 2 hrs 1 day Thu 23-03-09 Thu 23-03-09 Project Manager[13%],Program Manager 
7.3.185 Schedule Management 185. | 2 hrs 1 day Thu 23-03-16 Thu 23-03-16 Project Manager[13%],Program Manager 
7.3.186 Schedule Management 186 2 hrs 1 day Thu 23-03-23 Thu 23-03-23 Project Manager[13%],Program Manager 
7.3.187 Schedule Management 187 2hrs 1 day Thu 23-03-30 Thu 23-03-30 Project Manager{13%],Program Manager 
7.3.188 Schedule Management 188 :2 hrs 1 day Thu 23-04-06 | Thu 23-04-06 Project Manager[13%],Program Manager 
7.3.189 Schedule Management 189 2 hrs a day Thu 23-04-13 ‘Thu 23-04-13 Project Manager[13%], Program Manager — 
7.3.190 Schedule Management 190 2 hrs 1 day Thu 23-04-20 Thu 23-04-20 Project Manager[13%],Program Manager 
7.3.191 . Schedule Management 191 2hrs | 1 day Thu23-04-27 -Thu 23-04-27 Project Manager[1376], Program Manager 
7.3.192 Schedule Management 192 2hrs .1 day Thu 23-05-04 Thu 23-05-04 Project Manager[13%], Program Manager 
T3193 Schedule Management 193 — 2hrs 1 day Thu 23-05-11 Thu 23-05-11 Project Manager[13%], Program Manager 
73.194. Schedule Management 194 2 hrs 1 day | Thu 23-05-18 Thu 23-05-18 Project Manager[13%],Program Manager 
7.3.195 Schedule Management 195. 2 hrs 1 day Thu23-05-25 Thu 23-05-25 Project Manager[13%],Program Manager 
7.3.196 Schedule Management 196 :2 hrs 1 day Thu 23-06-01 — Thu 23-06-01 Project Manager[13%],Program Manager 
7.3.197 Schedule Management 197 2 hrs 1 day Thu 23-06-08 Thu 23-06-08 Project Manager[13%],Program Manager 
7.3.198 Schedule Management 198 2 hrs 1 day Thu 23-06-15 Thu 23-06-15 Project Manager[13%],Program Manager 
7.3.199 Schedule Management 199 2hrs 1 day Thu 23-06-22 Thu 23-06-22 Project Manager[13%],Program Manager 
7.3.200 Schedule Management 200 2hrs. 1 day Thu 23-06-29 Thu 23-06-29 Project Manager{13%], Program Manager 
7:3:201 Schedule Management 201 _2 hrs 1day Thu 23-07-06 Thu 23-07-06 Project Manager[13%],Program Manager 
7.3.202 Schedule Management 202 2 hrs .. day Thu 23-07-13 Thu 23-07-13 © Project Manager[13%],Program Manager 
7.3.203 Schedule Management 203 2hrs : 1 day Thu 23-07-20 Thu 23-07-20 Project Manager[13%],Program Manager 
7.3.204 Schedule Management 204 2 hrs 1 day Thu 23-07-27 Thu 23-07-27 Project Manager[13%],Program Manager 
'7.3.205 Schedule Management 205 | 2 hrs 1 day | | Thu 23-08-03 Thu 23-08-03 Project Manager[13%], Program Manager 
7.3.206 Schedule Management 206 2 hrs 1 day Thu 23-08-10 Thu 23-08-10 Project Manager[13%],Program Manager 
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7.3.207 Schedule Management 207 2 hrs. 1 day Thu 23-08-17 Thu 23-08-17 Project Manager[13%],Program Manager 
7.3.208 Schedule Management 208 2 hrs 1day Thu 23-08-24 Thu 23-08-24 Project Manager[13%],Program Manager 
7.3.209 Schedule Management 209 . 2hrs | :1 day Thu 23-08-31 Thu 23-08-31 Project Manager[13%],Program Manager 
7.3.210 Schedule Management 210 _ 2 hrs 1 day ‘Thu 23-09-07 Thu 23-09-07 Project Manager[13?6], Program Manager _ 
73.211 Schedule Management 211 2 hrs :1 day Thu 23-09-14 Thu 23-09-14 Project Manager[13%],Program Manager 
:7.3.212 _ Schedule Management 212 2 hrs 1 day | Thu 23-09-21 Thu 23-09-21 Project Manager[13%],Program Manager 
:7.3.213 Schedule Management 213 | 2 hrs '1day Thu 23-09-28 © Thu 23-09-28 Project Manager[1396],Program Manager 
7.3.214 Schedule Management 214 2hrs — 1 day. Thu 23-10-05 Thu 23-10-05 . ;Project Manager[13%],Program Manager 
7:315 _ Schedule Management 215 2 hrs .1 day Thu23-10-12 Thu 23-10-12 | Project Manager[13%],Program Manager _ 
7.3.216 Schedule Management 216 2hrs | 1 day Thu 23-10-19 Thu 23-10-19 Project Manager[13%],Program Manager 
7.3.217 _ Schedule Management 217 2hrs | 1 day Thu 23-10-26 Thu 23-10-26 Project Manager{13%],Program Manager- 
7.3.218 Schedule Management 218 | 2 hrs 1 day Thu 23-11-02 Thu 23-11-02 Project Manager[13%],Program Manager 
23.219 Schedule Management 219 2 hrs 1 day .Thu23-11-09 Thu 23-11-09 Project Manager[13%],Program Manager 
7.3.220 Schedule Management 220 2 hrs 1 day | Thu 23-11-16 Thu 23-11-16 Project Manager[13%],Program Manager 
73.221 Schedule Management 221 2 hrs 1 day Thu 23-11-23 Thu 23-11-23 Project Manager[13%],Program Manager 
73.222. Schedule Management 222 :2 hrs 1 day Thu 23-11-30 Thu 23-11-30 Project Manager[13%],Program Manager 
7.3.223 Schedule Management 223 2 hrs 1 day ‘Thu 23-12-07 _ Thu 23-12-07 Project Manager[13%],Program Manager 
7.3.224 Schedule Management 224 2 hrs 1 day ‘Thu 23-12-14 Thu 23-12-14 © Project Manager[13%],Program Manager 
7.3.225 Schedule Management 225 2 hrs | 1 day ‘Thu 23-12-21 :Thu 23-12-21 Project Manager[13%],Program Manager 
7.3.226 Schedule Management 226 2hrs. 1 day :Thu 23-12-28 Thu 23-12-28 Project Manager[13%],Program Manager 
7.3227 Schedule Management 227 2 hrs 1 day Thu 24-01-04 Thu 24-01-04 Project Manager[13%],Program Manager 
7.3.228 Schedule Management 228 | 2 hrs 1 day Thu 24-01-11 Thu24-01-11 Project Manager[13%], Program Manager 
73.240 Schedule Management 229 2 hrs 1 day Thu 24-01-18 Thu 24-01-18 Project Manager[13%],Program Manager 
7.3.230 . Schedule Management 230 2 hrs 1 day Thu 24-01-25 Thu 24-01-25. Project Manager[13%],Program Manager 
7.3.231 Schedule Management 231 2 hrs 1 day «Thu 24-02-01 Thu 24-02-01 Project Manager[13?6],Program Manager 
T.3.232 Schedule Management 232 2 hrs 1 day Thu 24-02-08 Thu 24-02-08 Project Manager[13%], Program Manager 
7.3.233 Schedule Management 233 2 hrs 1 day Thu 24-02-15 . Thu 24-02-15 Project Manager[13%],Program Manager 
73234 Schedule Management 234 2 hrs | 1 day Thu 24-02-22 Thu 24-02-22 : Project Manager[1326],Program Manager 
7.3,235 Schedule Management 235 2 hrs 1 day Thu 24-02-29 Thu 24-02-29 Project Manager[13%],Program Manager 
73.236 Schedule Management 236 2 hrs .1 day Thu 24-03-07 Thu 24-03-07 _ Project Manager[13%],Program Manager 
7.3.237 Schedule Management 237 2 hrs 1 day Thu 24-03-14 . Thu 24-03-14 Project Manager[13%], Program Manager 
13:38: Schedule Management 238 2 hrs .1 day Thu 24-03-21 Thu 24-03-21 Project Manager[1396],Program Manager 
T3439 Schedule Management 239 2 hrs :1 day Thu 24-03-28 Thu 24-03-28 . Project Manager[13%],Program Manager 
7.3.240 Schedule Management 240 2 hrs 1 day Thu 24-04-04 Thu 24-04-04 Project Manager[13?6], Program Manager 
7.3.241 Schedule Management 241 _2 hrs 1 day Thu 24-04-11 Thu 24-04-11 Project Manager[13%],Program Manager 
7.3.242 _ Schedule Management 242 2 hrs 1 day Thu 24-04-18 = Thu 24-04-18 — . Project Manager[13%],Program Manager — 
7.3.243 Schedule Management 243 2hrs | 1 day Thu 24-04-25 ‘Thu 24-04-25 © Project Manager[13%],Program Manager _ 
7.3.244 Schedule Management 244 | 2 hrs 1day | Thu 24-05-02 Thu 24-05-02 Project Manager[1396], Program Manager _ 
7.3.245 — Schedule Management 245 _2 hrs | 1 day Thu 24-05-09 Thu 24-05-09 Project Manager[13%],Program Manager 
7.3.246 | _ Schedule Management 246 2 hrs 1 day Thu 24-05-16 Thu 24-05-16 Project Manager[13%],Program Manager 
7.3.247 Schedule Management 247 2 hrs E 1 day Thu 24-05-23 . Thu 24-05-23 Project Manager[13%],Program Manager 
7.3.248 Schedule Management 248 2 hrs 1day |. Thu 24-05-30 Thu 24-05-30 Project Manager[13?6], Program Manager 
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7.3.249 Schedule Management 249 


7.3.250 Schedule Management 250 
73.251 Schedule Management 251 
7.3.252 Schedule Management 252 
7.3.253 Schedule Management 253 
7.3.254 Schedule Management 254 
7.3.255 Schedule Management 255 
7.3.256 _ Schedule Management 256 
7.3.257 Schedule Management 257 
73.258 Schedule Management 258 
13.209 Schedule Management 259 
7.3.260 Schedule Management 260 
73.261 _ Schedule Management 261 
7.3.262 Schedule Management 262 
7.3.263 Schedule Management 263 
7.3.2564 Schedule Management 264 
7.3.265 Schedule Management 265 ž 
7.3.266 Schedule Management 266 
13.267 Schedule Management 267 
7.3.268 Schedule Management 268 
7.3.269 Schedule Management 269 
7.4 | Budget management 

7.4.1 | Budget management 1 
7.4.2 : Budget management 2 
JA3 000 | Budget management 3 
744 Budget management 4 
7.4.5 < Budget management 5 
7.4.6 ... Budget management 6 
7.4.7 |. Budget management 7 
7.4.8 Budget management 8 
749 SENN Budget management 9 
7.4.10 Budget management 10 
7411 | | | Budget management 11 
7.4.12 Budget management 12 
7.4.13 Budget management 13 
7.4.14 Budget management 14 
7415 — _ Budget management 15 
7.416 ... Budget management 16 - 
7.4.17 Budget management 17 
7.4.18 | Budget management 18 
7.4.19 Budget management 19 
7.4.20 Budget management 20 
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Tue 21-04-06 


Finish 
Thu 24-06-06 


-Thu 24-06-13 


Thu 24-06-20 


Thu24-06-27 . 
Thu 24-07-04 


Thu 24-07-11 
Thu 24-07-18 
Thu 24-07-25 


Thu 24-08-01 
Thu 24-08-08 


Thu 24-08-15. 


“Thu 24-08-22 


Thu 24-08-29 


Thu 24-09-05 
Thu 24-09-12 


Thu 24-09-19 


‘Thu 24-09-26 - 
— Thu 24-10-03 
Thu 24-10-10 


Thu 24-10-17 


| Thu 24-10-24 


Fri 24-11-01 
Fri 19-09-06 
Fri 19-10-04 - 
Fri 19-11-01 - 
Fri 19-12-06 
Fri 20-01-03 


‘Fri 20-02-07 
Fri 20-03-06 


Fri 20-04-03 
Fri 20-05-01 


: Fri 20-06-05 


Fri 20-07-03 
Fri 20-08-07 
Fri 20-09-04 


Fri 20-10-02 _ 
Fri 20-11-06 
Fri 20-12-04 


Mon 21-01-04 
Fri 21-02-05 
Fri 21-03-05 


| Tue 21-04-06 


Predecessors 
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Project Manager{13%],Program Manager 
Project Manager[13%], Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
| Project Manager[13%],Program Manager 
‘Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


;Project Manager[13%],Program Manager 


L, 

Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
]; 
|; 
], 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
‘Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


‘Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[1326],Program Manager 
Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager _ i 
Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 


Project Manager[13%],Program Manager 
Project Manager[13%],Program Manager 
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7.4.21 Budget management 21 2 hrs :1 day Fri 21-05-07 Fri 21-05-07 Project Manager[13%],Program Manager 
7.4.22 Budget management 22 2 hrs 1 day Fri 21-06-04 Fri 21-06-04 Project Manager[13%] Program Manager 
7.4.23 Budget management 23 2 hrs 1 day Fri 21-07-02 Fri 21-07-02 Project Manager[13%],Program Manager 
7.4.24 . Budget management 24 2hrs | 1 day Fri 21-08-06 Fri 21-08-06 Project Manager[13%],Program Manager 
7.4.25 . Budget management 25 .2 hrs 1 day :Fri 21-09-03 Fri 21-09-03 © Project Manager[13?6],Program Manager 
7.4.26 Budget management 26 2 hrs 1 day Fri 21-10-01 Fri 21-10-01 Project Manager[1396],Program Manager 
7.4.27 Budget management 27 - 2 hrs _ 1 day _ Fri 21-11-05 Fri 21-11-05 Project Manager[13%],Program Manager 
7.4.28 Budget management 28 2 hrs _.1 day ;Fri 21-12-03 Fri 21-12-03 Project Manager[13?6], Program Manager. 
7.4.29 Budget management 29 2 hrs 1 day Fri 22-01-07 Fri 22-01-07 . Project Manager[13%],Program Manager 
7.4.30 Budget management 30 2 hrs '1 day Fri 22-02-04 Fri 22-02-04. Project Manager[1326], Program Manager 
7.4.31 _ Budget management 31 2 hrs 1day Fri 22-03-04 Fri 22-03-04 Project Manager[13%],Program Manager 
7.4.32 l Budget management 32 2 hrs clday | Fri 22-04-01 Fri 22-04-01 o. Project Manager[13?6], Program Manager 
7.4.33 Budget management 33 2 hrs . day Fri 22-05-06 Fri 22-05-06 .;Project Manager[13%],Program Manager 
7.4.34 Budget management 34 2 hrs 1 day Fri 22-06-03 Fri 22-06-03 Project Manager[13%], Program Manager 
7.4.35 Budget management 35 2 hrs 1 day Mon 22-07-04 Mon 22-07-04 Project Manager[13%],Program Manager 
7.4.36 Budget management 36 2 hrs .1 day Fri 22-08-05 Fri 22-08-05 Project Manager[13%],Program Manager 
7.4.37 Budget management 37. 2 hrs 1 day Fri 22-09-02 . Fri 22-09-02 Project Manager[13%],Program Manager 
7.4.38 Budget management 38 2 hrs .1 day Fri 22-10-07 Fri 22-10-07 Project Manager[13%],Program Manager 
7.4.39 Budget management 39 2 hrs 1 day Fri 22-11-04 Fri 22-11-04 Project Manager[13%], Program Manager _ 
7.4.40. Budget management 40 2 hrs 1 day Fri 22-12-02 Fri 22-12-02 Project Manager[13%],Program Manager _ 
7.4.41 Budget management 41 2 hrs 1 day Fri 23-01-06. u Fri 23-01-06 Project Manager[13%],Program Manager 
7.4.42 Budget management 42 2 hrs 1 day Fri 23-02-03 Fri 23-02-03 _ Project Manager[13?6], Program Manager 
7.4.43 Budget management 43 :2 hrs 1 day Fri 23-03-03 Fri 23-03-03 Project Manager[13%],Program Manager 
7.4.44 Budget management 44 2hrs l day Fri 23-04-07 Fri 23-04-07 Project Manager[13%], Program Manager 
7.4.45 Budget management 45 _2hrs | 1 day Fri 23-05-05 Fri 23-05-05 Project Manager[13%],Program Manager . 
7.4.46 Budget management 46 :2 hrs :1 day Fri 23-06-02 Fri 23-06-02 Project Manager[1396],Program Manager 
7.4.47 Budget management 47 2hrs | day | Fri 23-07-07 Fri 23-07-07 Project Manager[13*6], Program Manager 
7.4.48 Budget management 48 2 hrs 1 day Fri 23-08-04 Fri 23-08-04 Project Manager[13%],Program Manager 
7.4.49 Budget management 49 2 hrs :1 day Fri 23-09-01 Fri 23-09-01 Project Manager[13%],Program Manager 
7.4.50 Budget management 50 | 2 hrs 1 day | Fri 23-10-06 Fri 23-10-06 Project Manager[13%],Program Manager 
7.4.51 Budget management 51 2 hrs 1day | “Fri 23-11-03 Fri 23-11-03 Project Manager[13%], Program Manager 
7.4.52 Budget management 52 2 hrs 1 day Fri 23-12-01 Fri 23-12-01 Project Manager[13%],Program Manager 
7.4.53 Budget management 53 2 hrs :1 day Fri 24-01-05 Fri 24-01-05 - Project Manager[1396],Program Manager 
7.4.54 Budget management 54 2 hrs 1 day Frì 24-02-02 Fri 24-02-02 -Project Manager[13%],Program Manager 
7.4.55 Budget management 55 2 hrs | 1day Fri 24-03-01 Fri 24-03-01 Project Manager[13%],Program Manager . 
7.4.56. Budget management 56 2 hrs :1 day Fri 24-04-05 — Fri 24-04-05 Project Manager[13%],Program Manager | 
7.4.57 Budget management 57 2 hrs :1 day Fri 24-05-03 Fri 24-05-03 Project Manager[13%],Program Manager — — 
7.4.58 Budget management 58 2 hrs 1 day Fri 24-06-07 Fri 24-06-07 Project Manager[13%],Program Manager 
7.4.59 Budget management 59 2 hrs 1 day Fri 24-07-05 Fri 24-07-05 Project Manager[13%],Program Manager 
7.4.60 Budget management 60 2 hrs 1 day Fri 24-08-02 .Fri 24-08-02 Project Manager[13%],Program Manager 
7.4.61 Budget management 61 2 hrs 1 day Fri 24-09-06 Fri 24-09-06 _ . Project Manager[13%],Program Manager 
7.4.62 Budget management 62 '2 hrs 1 day Fri 24-10-04 Fri 24-10-04 ‘Project Manager[13%],Program Manager 
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7.4.63 Budget management 63 _ — _.2 hrs 1 day | Fri 24-11-01 Fri 24-11-01 | Project Manager[13%],Program Manager 
7.5 Risk management review and analysis 126 hrs 1394.07 days Fri 19-09-06 Fri 24-11-01 -— | | "" 
7.5.1 Risk management review and analysis 1 2hrs | _ :1day Fri 19-09-06 Fri 19-09-06 Project Manager[13%],Program Manager 
7.5.2 Risk management review and analysis 2 :2 hrs | -1 day Fri 19-10-04 Fri 19-10-04 ' Project Manager[13%], Program Manager 
7.5.3 Risk management review and analysis 3 2 hrs 1 day Fri 19-11-01 Fri 19-11-01 Project Manager[13%],Program Manager 
7.5.4 Risk management review and analysis 4 2hrs 1 day | Fri 19-12-06 Fri 19-12-06 Project Manager[13%],Program Manager 
7.5.5 Risk management review and analysis 5 2 hrs 1 day Fri 20-01-03 Fri 20-01-03 | Project Manager[13%],Program Manager 
7.5.6 Risk management review and analysis 6 2hrs 1 day Fri 20-02-07 Fri 20-02-07 Project Manager[13%],Program Manager 
7.5.7 Risk management review and analysis 7 2 hrs 1 day Fri 20-03-06 Fri 20-03-06 Project Manager[13%],Program Manager 
7.5.8. Risk management review and analysis 8 | 2 hrs 1 day Fri 20-04-03 Fri 20-04-03 Project Manager[13%],Program Manager 
7:5:9 Risk management review and analysis 9 2hrs 1 day Fri 20-05-01 . Fri 20-05-01 . Project Manager[13%],Program Manager 
7.5.10 Risk management review and analysis 10 2hrs 1 day Fri 20-06-05 Fri 20-06-05 | Project Manager[13%], Program Manager 
7.5.11 Risk management review and analysis 11  2hrs 1 day Fri20-07-03 Fri 20-07-03. Project Manager[1396],Program Manager 
7.5.12 _ Risk management review and analysis 12 _ 2hrs | .1 day Fri 20-08-07 Fri 20-08-07 Project Manager[13%],Program Manager 
7.5.13 Risk management review and analysis 13 2 hrs .1 day : Fri 20-09-04 NE Fri 20-09-04 Project Manager[13*6], Program Manager 
7.5.14 Risk management review and analysis 14 _ 2 hrs 1 day : Fri 20-10-02 Fri 20-10-02 Project Manager{13%J],Program Manager 
7.5.15 Risk management review and analysis 15_ | 2 hrs 1 day ‘Fri 20-11-06 Fri 20-11-06 Project Manager[13%],Program Manager 
7.5.16 Risk management review and analysis 16 2 hrs 1 day | Fri 20-12-04 Fri 20-12-04 Project Manager[1396],Program Manager 
7.5.17 Risk management review and analysis 17 2hrs ë :1 day ‘Mon 21-01-04 Mon 21-01-04 Project Manager[13%],Program Manager 
7.5.18 Risk management review and analysis 18. _.2hrs_ 1 day Fri 21-02-05 Fri 21-02-05 Project Manager[13%],Program Manager 
7.5.19 Risk management review and analysis 19 i2 hrs 1 day j Fri 21-03-05 Fri 21-03-05 _ Project Manager[13?6], Program Manager 
7.5.20 Risk management review and analysis 20 2 hrs 1 day ¿Tue 21-04-06 Tue 21-04-06 Project Manager[13?6],Program Manager 
7.5.21 Risk management review and analysis 21 2 hrs day _ Fri 21-05-07 Fri 21-05-07 - _ Project Manager[13%],Program Manager 
7.5.22 Risk management review and analysis 22 2 hrs 1 day : Fri 21-06-04 Fri 21-06-04 Project Manager[13%],Program Manager 
1323 Risk management review and analysis 23 2 hrs .1 day Fri 21-07-02 Fri 21-07-02 .— Project Manager[13%],Program Manager 
7.5.24 Risk management review and analysis 24 2 hrs 1 day Fri 21-08-06 Fri 21-08-06 Project Manager[13%],Program Manager 
7.5.25 Risk management review and analysis 25 2 hrs '1 day Fri 21-09-03 .. .Fri 21-09-03 Project Manager[13%],Program Manager Žž — 
7.5.26 Risk management review and analysis 26 2 hrs d day | Fri 21-10-01 Fri 21-10-01 Project Manager[1396],Program Manager _ 
7.5.27 Risk management review and analysis 27 2 hrs :1 day Fri 21-11-05 Fri 21-11-05 Project Manager[13%],Program Manager 
7.5.28 Risk management review and analysis 28 :2 hrs 1 day Fri21-12-03 _ Fri 21-12-03 ‘Project Manager[13%],Program Manager 
7.5.29 Risk management review and analysis 29 2 hrs 1 day Fri 22-01-07 Fri 22-01-07 Project Manager[13%],Program Manager 
7.5.30 Risk management review and analysis 30 — 2hrs :1 day Fri 22-02-04 Fri 22-02-04 : Project Manager[13%],Program Manager 
7531. Risk management review and analysis 31 | :2 hrs :1 day Fri 22-03-04 Fri 22-03-04 Project Manager[13%],Program Manager 
7.5.32 Risk management review and analysis 32 2hrs 1 day Fri 22-04-01 Fri 22-04-01 Project Manager[13%],Program Manager 
7.5.33 Risk management review and analysis 33 :2 hrs 1 day Fri 22-05-06 Fri 22-05-06 Project Manager[13%],Program Manager 
7.5.34 Risk management review and analysis 34 - 2 hrs 1 day Fri 22-06-03 Fri 22-06-03 Project Manager[13%],Program Manager 
d. 95. Risk management review and analysis 35 2 hrs 1 day Mon 22-07-04 Mon 22-07-04 Project Manager[13%],Program Manager 
7.5.36. | Risk management review and analysis 36 2hrs 1 day | Fri 22-08-05 Fri 22-08-05 Project Manager[13?6], Program Manager p 
7.5.37 Risk management review and analysis 37 2hrs âi day Fri 22-09-02 — Fri 22-09-02 Project Manager[13%],Program Manager 
7.5.38 Risk management review and analysis 38 2 hrs 1 day Fri 22-10-07 Fri 22-10-07 Project Manager[13%],Program Manager 
7.5.39 Risk management review and analysis 39 .2 hrs :1 day Fri 22-11-04 Fri 22-11-04 Project Manager[13%],Program Manager 
7.5.40 Risk management review and analysis 40 2 hrs 1 day : Fri 22-12-02 Fri 22-12-02 Project Manager[13%],Program Manager 
Smart Cities Challenge Proposal Project Plan City of Airdrie 37 of 40 
Processed under the provisions of the Access to Page 333 of 341 


Information Act /Révisé en vertu de la Loi sur l'accés 
à l'information 


WBS Task Name... Work Duration Start Finish Predecessors Resource Names 
7.5.41 Risk management review and analysis 41 2 hrs . day Fri 23-01-06 ‘Fri 23-01-06 Project Manager[1396],Program Manager 
7.5.42 Risk management review and analysis 42 2 hrs 1 day Fri 23-02-03 . Fri 23-02-03 Project Manager[13%],Program Manager 
7.5.43 Risk management review and analysis 43 2 hrs 1 day Fri 23-03-03 ‘Fri 23-03-03 Project Manager[13%],Program Manager _ 
7.5.44 _Risk management review and analysis 44 _ 2 hrs 1 day Fri 23-04-07 Fri 23-04-07 . Project Manager[1396], Program Manager 
7.5.45 . Risk management review and analysis 45 2 hrs 1day  . Fri 23-05-05 Fri 23-05-05 Project Manager[13%],Program Manager - 
7.5.46 Risk management review and analysis 46 2hrs i day . Fri 23-06-02 Fri 23-06-02 Project Manager[13%],Program Manager 
7.5.47 — Risk management review and analysis 47 2 hrs :1 day Fri 23-07-07 Fri 23-07-07 - Project Manager[139?6], Program Manager 
7.5.48 Risk management review and analysis 48 2 hrs .1 day Fri 23-08-04 ‘Fri 23-08-04 Project Manager[13%],Program Manager 
7.5.49 _Risk management review and analysis 49 2 hrs 1 day Fri 23-09-01 Fri 23-09-01 Project Manager[1396],Program Manager 
7.5.50 Risk management review and analysis 50 2 hrs 1 day Fri 23-10-06 Fri 23-10-06 Project Manager[13%], Program Manager 
7.5.51 Risk management review and analysis 51 2 hrs .1 day Fri 23-11-03 Fri 23-11-03 Project Manager[1396], Program Manager 
7.5.52 Risk management review and analysis 52 2hrs d day Fri 23-12-01 Fri 23-12-01 ‘Project Manager[13%],Program Manager 
7.5.53 Risk management review and analysis 53 2 hrs 1 day Fri 24-01-05 Fri 24-01-05 — Project Manager[13*6], Program Manager 
7.5.54 Risk management review and analysis 54 2hrs | 1 day Fri 24-02-02 Fri 24-02-02 Project Manager[13?6], Program Manager 
Too Risk management review and analysis 55 2 hrs .1 day Fri 24-03-01 Fri 24-03-01 Project Manager[13%],Program Manager 
7.5.56 Risk management review and analysis 56 2 hrs 1 day Fri 24-04-05 Fri 24-04-05 Project Manager[1326], Program Manager 
7.5.57 Risk management review and analysis 57 _ :2 hrs 1 day. Fri 24-05-03 Fri 24-05-03 Project Manager[13?6], Program Manager 
7.5.58 Risk management review and analysis 58 2 hrs 1 day Fri 24-06-07 Fri 24-06-07 Project Manager[13?6], Program Manager 
7.5.59 Risk management review and analysis 59 2 hrs :1 day Fri 24-07-05 Fri 24-07-05 Project Manager[1396], Program Manager 
7.5.60 Risk management review and analysis 60 2 hrs 1 day Fri 24-08-02 Fri 24-08-02 Project Manager[13%],Program Manager 
7.5.61 Risk management review and analysis 61 2 hrs 1 day Fri 24-09-06 Fri 24-09-06 Project Manager[13%],Program Manager 
7.5.62 Risk management review and analysis 62 _2hrs 1day _ Fri 24-10-04 Fri 24-10-04 Project Manager[13%],Program Manager _ 
7.5.63. Risk management review and analysis 63 2 hrs 1 day .. .Fri 24-11-01 Fri 24-11-01 Project Manager[13%],Program Manager _ 
7.6 Create project status report 126 hrs 1394.07 days Fri 19-09-06 Fri 24-11-01 NA 
7.6.1 Create project status report 1 2 hrs 1 day | Fri 19-09-06 Fri 19-09-06 Project Manager[1396],Program Manager 
7.6.2 Create project status report 2 2hrs _ :1 day :Fri 19-10-04 Fri 19-10-04 Project Manager[13%],Program Manager 
7.6.3 Create project status report 3 2 hrs :1 day Fri 19-11-01 Fri 19-11-01 Project Manager[13%],Program Manager 
7.64 . Create project status report 4 2 hrs .1 day Fri 19-12-06 Fri 19-12-06 Project Manager[1396], Program Manager 
7.6.5 _ Create project status report 5 2 hrs 1 day Fri 20-01-03 Fri 20-01-03 Project Manager[1396], Program Manager 
7.6.6. Create project status report 6 2 hrs 1 day Fri 20-02-07 Fri 20-02-07 Project Manager{13%],Program Manager 
7.6.7 Create project status report 7 2 hrs 1 day Fri 20-03-06 Fri 20-03-06 Project Manager[13?6],Program Manager 
7.6.8 Create project status report 8 2 hrs 1 day Fri 20-04-03 Fri 20-04-03 Project Manager[1326],Program Manager 
7.6.9 Create project status report 9 2 hrs 1 day Fri 20-05-01 Fri 20-05-01 Project Manager[13%],Program Manager 
7.6.10 Create project status report 10 2 hrs 1 day Fri 20-06-05 .Fri 20-06-05 Project Manager[13?6], Program Manager 
7.6.11 Create project status report 11 2 hrs _ i day Fri 20-07-03 Fri 20-07-03 ‘Project Manager[1326], Program Manager 
7.6.12 Create project status report 12 2 hrs .1 day Fri 20-08-07 Fri 20-08-07 _ Project Manager[13%],Program Manager 
7.6.13 . Create project status report 13 2 hrs 1 day Fri 20-09-04 Fri 20-09-04 |. Project Manager[13%],Program Manager 
7.6.14 Create project status report 14 2 hrs 1 day Fri 20-10-02 Fri 20-10-02 Project Manager[1326], Program Manager 
7.6.15 Create project status report 15 2 hrs 1 day Fri 20-11-06 Fri 20-11-06 | Project Manager[13%],Program Manager 
7.6.16 | Create project status report 16 | | 2hrs __:1 day Fri 20-12-04 Fri 20-12-04 Project Manager[13%],Program Manager 
7.6.17 i Create project status report 17 | 2 hrs | | 1 day Mon 21-01-04 Mon 21-01-04 Project Manager[13%],Program Manager 
7.6.18 Create project status report 18 =, a2 RES 1 day Fri 21-02-05 Fri 21-02-05 Project Manager[13%],Program Manager 
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26,49 Create project status report 19 2hrs | ...:1 day Fri 21-03-05 — Fri 21-03-05 Project Manager[13?6],Program Manager 
7:6.20 Create project status report 20 2 hrs ..1 day Tue 21-04-06 Tue 21-04-06 Project Manager[13%],Program Manager . 
7.6.21 Create project status report 21 2 hrs 1day . Fri 21-05-07 Fri 21-05-07 Project Manager[13%],Program Manager 
7.6.22 Create project status report 22 — 2hrs | 1day | Fri 21-06-04 Fri 21-06-04 Project Manager[13%], Program Manager 
7.6.23 Create project status report 23 2 hrs 1 day Fri 21-07-02 Fri 21-07-02 Project Manager[1326], Program Manager 
7.6.24 Create project status report 24 2 hrs 1 day Fri 21-08-06 Fri 21-08-06 Project Manager[1396],Program Manager. 
7.6.25 Create project status report 25 2 hrs :1 day Fri 21-09-03 Fri 21-09-03 | Project Manager[13%],Program Manager 
7.6.26 Create project status report 26 2hrs 1 day Fri 21-10-01 Fri 21-10-01 . Project Manager[13%],Program Manager 
7.6.27 Create project status report 27 2 hrs ‘1 day Fri 21-11-05 Fri 21-11-05 Project Manager[13%],Program Manager 
76:28 Create project status report 28 2 hrs 1day  J  Fri21-12-03 Fri 21-12-03 Project Manager[13%],Program Manager 
7.6.29 Create project status report 29 2hrs 1 day -Fri 22-01-07 Fri 22-01-07 Project Manager[13%], Program Manager 
7.6.30 Create project status report 30 2hrs _:1 day Fri22-02-04 Fri 22-02-04 | Project Manager{[13%], Program Manager _ 
7.6.31 Create project status report 31 2 hrs 1 day Fri 22-03-04 Fri 22-03-04 Project Manager[132],Program Manager 
7.6.32 Create project status report 32 2 hrs 1 day Fri 22-04-01 Fri 22-04-01 Project Manager[1396],Program Manager 
4.5.33 Create project status report 33 2 hrs 1 day Fri 22-05-06 Fri 22-05-06 Project Manager[13%],Program Manager 
7.6.34 Create project status report 34 2 hrs 1 day Fri 22-06-03 Fri 22-06-03 ' Project Manager[13%],Program Manager 
7.6.35 _Create project status report 35 2 hrs 1 day Mon 22-07-04 Mon 22-07-04 Project Manager[13%],Program Manager 
7.6.36 Create project status report 36 2hrs .1 day Fri 22-08-05 Fri 22-08-05 Project Manager[13%],Program Manager t 
7.6.37 . Create project status report 37 2 hrs 1 day Fri 22-09-02 Fri 22-09-02 © Project Manager[13%],Program Manager 
7.6.38 Create project status report 38 2hrs — 1 day Fri 22-10-07 Fri 22-10-07 _ Project Manager[13%],Program Manager 
7.6.39 Create project status report 39 2hrs. i 1 day Fri 22-11-04 Fri 22-11-04 Project Manager[13%],Program Manager 
7.6.40 Create project status report 40 2 hrs 1 day Fri 22-12-02 Fri 22-12-02 Project Manager[1396], Program Manager 
7.6.41 Create project status report 41 2hrs 1 day. Fri 23-01-06 Fri 23-01-06 | Project Manager[13%],Program Manager 
7.6.42 Create project status report 42 2 hrs :1 day Fri 23-02-03 Fri 23-02-03 Project Manager[1326],Program Manager 
7.6.43 Create project status report 43. 2hrs | '1day Fri 23-03-03 Fri 23-03-03 Project Manager[13%],Program Manager 
7.6.44 Create project status report 44 2hrs | 1 day Fri 23-04-07 Fri 23-04-07 Project Manager[13%],Program Manager 
7.6.45 Create project status report 45 2 hrs .1 day Fri 23-05-05 Fri 23-05-05 © Project Manager[13%],Program Manager 
7.6.46 Create project status report 46 2 hrs 1 day :Fri 23-06-02 Fri 23-06-02 | Project Manager[13%],Program Manager 
7.6.47 | Create project status report 47 2hrs 1 day Fri 23-07-07 Fri 23-07-07 ;Project Manager[13%],Program Manager 
7.6.48 Create project status report 48 2 hrs .1 day Fri 23-08-04 Fri 23-08-04 Project Manager[13%],Program Manager 
7.6.49 . Create project status report 49 2 hrs 1 day Fri 23-09-01 Fri 23-09-01 Project Manager[1396],Program Manager 
7.6.50 Create project status report 50 2 hrs ‘1 day Fri 23-10-06 Fri 23-10-06 Project Manager[13%],Program Manager 
7.6.51 Create project status report 51 2 hrs 1 day Fri 23-11-03 Fri 23-11-03 Project Manager[13%],Program Manager 
7.6.52 Create project status report 52 2 hrs 1 day Fri 23-12-01 Fri 23-12-01 Project Manager[1396],Program Manager 
7.6.53 Create project status report 53 2 hrs |... day Fri 24-01-05 Fri 24-01-05 _ Project Manager[13%], Program Manager 
7.6.54 Create project status report 54 2hrs | d day “Fri 24-02-02 Fri 24-02-02 :Project Manager[13?6], Program Manager 
4595. Create project status report 55 2 hrs 1 day Fri 24-03-01 Fri 24-03-01 Project Manager[13%],Program Manager _ 
7.6.56 Create project status report 56 2hrs 1 day Fri 24-04-05 Fri 24-04-05 Project Manager[13%],Program Manager 
:7.6.57 Create project status report 57 :2 hrs :1 day Fri 24-05-03 Fri 24-05-03 Project Manager[13%],Program Manager 
7.6.58 Create project status report 58 2 hrs :1 day Fri 24-06-07 Fri 24-06-07 Project Manager[1326], Program Manager 
7.6.59 Create project status report 59 2 hrs 1 day -Fri 24-07-05 -Fri 24-07-05 Project Manager[13%],Program Manager 
7.6.60 Create project status report 60 2hrs | :1 day Fri 24-08-02 Fri 24-08-02 Project Manager[13%],Program Manager _ 
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7.6.61 yn | Create project status report 61 uu 2 hrs 1day Fri 24-09-06 Fri 24-09-06 Project Manager[13%],Program Manager 
7.6.62 Create project status report 62 u 2 hrs 1 day Fri 24-10-04 Fri 24-10-04 Project Manager[13%],Program Manager 
7.6.63 Žž Create project status report 63 | o INE IC 1 day Fri 24-11-01 Fri 24-11-01 


Project Manager[13%], Program Manager 
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Transcription of: What is API? 


Connectivity is an amazing thing. By now we're all used to the instant connectivity that puts the 
world at our fingertips. From desktops or devises we can purchase post pin and pick anything 
anywhere — we are connected to the world and each other like never before. But how does it 
happen? How does data get from here to there? How do different devices and applications connect 
with each other to allow us to place an order, make a reservation, or book a flight with just a few 
types of things? The unsung hero of our connected world is it the application programming 
interface or API? It’s the engine under the hood and is behind the scenes that we take for granted 
but it’s what makes possible all the interactivity we’ve come to expect and rely upon but what 
exactly is an API? It’s a question everyone asks. Ok? Not really, but we're glad you did. The 
textbook goes something like this: in computer programming: an application programming 
interface (API) is a set of routine protocols. To speak plainly, an API is the messenger that takes 
requests and tells a system what you want to do and then returns the response back to you. To 
give you a familiar example, think of an API as a waiter in a restaurant. Imagine youre sitting at 
the table with a menu of choices to order from and the kitchen is the part of the system which will 
prepare your order. What's missing is the critical link to communicate your order to the kitchen 
and delver your food back to your table. That's where the waiter or API come in. The waiter is the 
messenger that takes your reguest or order and tells the system- in this case the kitchen - what to 
do and the response back to you, in this case food. Now that we've whetted your appetite, let's 
apply this to a real API example you are probably familiar with. The process of searching for airline 
online, just like at a restaurant, you have a menu of options to choose from, a drop-down menu in 
this case. You choose a departure city and date, a return city and date tabbing clasp and other 
variables in order to book your flight. You interact with the airlines website to access the airline's 
database to see if any seats are available on those dates and what the cost might be based on 

. certain variables but what if you're not using the Airlines website which has direct access to the 
information? What if you are using an online travel service that aggregates information from 
many different airlines? The travel service interacts with the airlines’ API. The API is the interface 
that, like you're helpful waiter, can be asked by that online travel service to get information from 
the airline system over the internet to book seats choose meal preferences or baggage options. It 
also then take the airline's response to your reguest and delivers it right back to the online travel 
service which then shows it to you so now you can see that it's APT's that make it possible for us 
all to use travel sites. The same goes for all interactions between applications, data, and devices, 
they all have API's that allow computers to operate them and that's what ultimately creates 
connectivity. So, whenever you think of an API just think of it as your waiter running back and 
forth between applications, databases, and devices to deliver data and create the connectivity that 
puts the world at our fingertips and whenever you think of creating an API, think MuleSoft. 
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Lucas Mostazo, 14 Jan 2018. What is BLOCKCHAIN? The best explanation of blockchain 
technology. Retrieved from https://www.youtube.com/watch?v-3xGLce-zzocA 


Transcription of "What is BLOCKCHAIN? The best explanation of blockchain technology" 


Many people think of blockchain as the technology that powers Bitcoin. While this was its original 
purpose, blockchain is capable of so much more. Despite the sound of the word, there's not just one 
blockchain. Blockchain is shorthand for a whole suite of distributed ledger technologies that can be 
programmed to record and track anything of value, from financial transactions to medical records or even 
land titles. You might be thinking: we already have processes in place to track data. What's so special 
about blockchain? Let's break down the reasons why blockchain technology stands to revolutionize the 
way we interact with each other. Reason number one: the way it tracks and stores data. Blockchain stores 
information in batches called blocks that are linked together in a chronological fashion to form a 
continuous line: metaphorically, a chain of blocks. If you make a change to the information recorded in a 
particular block, you don't rewrite it. Instead the change is stored in a new block showing that x changed 
to y at a particular date and time. Sound familiar? That's because blockchain is based on the centuries-old 
method of the general financial ledger. It's a non-destructive way to track data changes over time. Here's 
one example. Let's say there was a dispute between Anne and her brother Steve over who owns a piece 
of land that's been in the family for years. Because blockchain technology uses the ledger method, there 
is an entry in the ledger showing that Adam first owned the property in 1900. When Adam sold the 
property to Dave in 1930, and new entry was made in the ledger, and so on. Every change of ownership 
of this property is represented by a new entry in the ledger, right up until Anne bought it from their father 
in 2007. Anne is the current owner and we can see that history in the ledger. Now, here's where things 
get really interesting. Unlike the age-old ledger method — originally a book then a database filed stored 
on a single system — blockchain was designed to be decentralized and distributed across a large network 
of computers. This decentralizing of information reduces the ability for data tampering and brings us to 
the second factor that make blockchain unique: it creates trust in the data. Before a block can be added 
to the chain, a few things have to happen. First, a cryptographic puzzle must be solved, thus creating the 
block. The computer that solves the puzzle shares the solution to all the other computers on the network, 
this is called proof-of-work. The network will then verify this proof-of-work and, if correct, the block will 
be added to the chain. The combination of these complex math puzzles and verification by many 
computers ensures that we can trust each and every block on the chain. Because the network does the 
trust building for us, we now have the opportunity to interact directly with our data in real-time. And this 
brings us to the third reason blockchain technology is such a game changer: no more intermediaries. 
Currently, when doing business with one another, we don't show the other person our financial or 
business records. Instead, we rely on trusted intermediaries, such as a bank or a lawyer to view our 
records, and keep that information confidential. These intermediaries build trust between the parties and 
are able to verify, for example, that, "Yes, Anne is the rightful owner of this land". This approach limits 
exposure and risk, but also adds another step to the exchange, which means more time and money spent. 
If Anne's land title information was stored in a blockchain, she could cut out the middleman, her lawyer, 
who would ordinarily confirm her information with Steve. As we now know, all blocks added to the chain 
have been verified to be true and can't be tampered with, so Anne can simply show Steve her land title 
information secured on the blockchain. Anne would save considerable time and money by cutting out the 
middleman. This type of trusted peer-to-peer interaction with our data can revolutionize the way we 
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access, verify and transact with one another. And because blockchain is a type of technology and not a 
single network, it can be implemented in many different ways. Some blockchains can be completely public 
and open to everyone to view and access. Others can be closed to a select group of authorized users 
(private blockchain) such as your company, a group of banks or government agencies. And then there are 
hybrid public-private blockchains too. In some, those with private access can see all the data, while the 
public can see only the selections. In others, everyone can see all the data, but only some people have 
access to add new data. A government, for example, could use a hybrid system to record the boundaries 
of Anne’s property and the fact that she owns it, while keeping her personal information private. Or it 
could allow everyone to view property records, but reserve to itself the exclusive right to update them. It 
is the combination of all of these factors — de-centralizing of the data, building trust in the data, and 
allowing us to interact directly with one another and the data — that gives blockchain technology the 
potential to underpin many of the ways we interact with one another. But, much like the rise of the 
internet, this technology will bring with it all kinds of complex policy questions around governance, 
international law, security and economics. Here at the Centre for International Governance Innovation, 
we seek to bring trusted research that will equip policy makers with the information they need to advance 
blockchain innovations, enabling economies to flourish in this new digital economy. 
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Hyperledger, 28 Apr 2017. Hyperledger Fabric Explainer. Retrieved 
from https: 'outube.com/watch?v-]s3Zjxbo8TM 


Transcription of "Hyperledger Fabric Explainer" 


Permissioned blockchain users that require every peer to execute every transaction, maintain a 
ledger and run consensus can't scale very well and they can't support true private transactions 
and contracts. So the hyperledger community designed Fabric V1 to deliver a truly modular, 
scalable and secure foundation for industrial blockchain solutions. The most notable change is 
the peers are decoupled into two separate run times with three distinct roles, endorser, 
committer and consenter. Here is how it works: say you run an organic market in California and 
| grow radishes on my farm in Chile. You and | are on a blockchain network that supports 
transactions between various markets, growers, shippers, banks and others. Say | agree to sell 
you my radishes at a special low price, but | need the other markets that buy from me to 
continue buying at the standard price. They shouldn't be able to execute our confidential 
agreement and find out the details of our deal. In fact, if they aren't part of the deal the 
transaction shouldn't appear on the ledger. Fabric V1 handles all this. My app looks up your 

identity from a membership service and then sends the transaction only to our peers. Both of 
our peers will generate a result. In this two party agreement the transaction requires both of us 
to render the same result, but in transactions with more parties other rules can apply. Then the 
peers send the validated transaction back to the application which sends it to a consensus 
Cloud for ordering and then the order transactions are sent back to the peers and committed to 
the ledger. But to get my radishes to your market there are many other parties involved. Some 
need to know that my radishes have been verified and checked into a shipping container, 
others need to handle bills of lading, customs inspections, financing, insurance, but most of 
these parties don't need to know about our special price. Now think about our transaction 
running on a network handling all the markets, all the farmers, shippers, facilitators, the whole 
supply chain. This is the same pattern needed by many industries, anywhere we need to 
manage confidential applications to each other without passing everything through a central 
authority. 


www.hyperledger.org 
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